Hacker News new | ask | show | jobs
by josephcsible 1860 days ago
Maybe having devices that can't be updated is not a good system.
1 comments

Having perfectly functional devices that become obsolete because the world moves around them is also not a good system. We don't have to design our support targets to be a moving window of >= $current_version - 2.
Arguing with time's arrow is fruitless. The world will change, it isn't going to wait around for your OK.

For the most part we aren't talking about needless turnover here. The trust store represents an institutional claim, between now and whenever you stop using this device, all the people who have these private keys will take proper care of them. I actually think that claim is extremely dubious for these Android devices today, it relies on people we meanwhile judged as incompetent to have nevertheless correctly destroyed key materials in their possession when they ceased to do business. I would not be astonished to discover that this already did not happen at least once since the devices ceased to get updates.

For example I imagine all the Symantec roots are included, and likewise StartCom/ WoSign.