|
|
|
|
|
by nmjohn
3271 days ago
|
|
> having a significant portion of the world's TLS be under one umbrella isn't a good thing. Why is that? The damage from a CA being hacked is not proportional to the size of the CA - they are all equally (small number of exceptions notwithstanding) capable of issuing certificates for any domain which will be trusted by all major browsers. Is there another aspect I'm not considering? While I see how it feels like a troubling thing, I'm struggling to actually come up with any real consequences of it. |
|