Hacker News new | ask | show | jobs
by 0x0 3539 days ago
Existing certs will continue to work until they expire. So "re-adding trust" to WoSign doesn't make sense. No sane site operator would renew their cert with WoSign since they will lose all Firefox and Apple clients.
1 comments

I wasn't saying it was a sane way to do it, just the easiest. I could also see it turning into a nationalism issue -- "The West is unfairly attacking native CAs." -- as impetus to try to convince people to manually trust and/or renew certs with them.