Hacker News new | ask | show | jobs
by throwaway32 5399 days ago
its much worse than that, there are an unknown amount of intermediate CAs that also have this abillity. Several CAs sell these certs freely. So not only can one of the 300 CAs get compromised and totally destroy ssl security, so can a large amount of people you have _no information about at all_.