Hacker News new | ask | show | jobs
by hmottestad 5323 days ago
Hmm. That sounds like a big security hole. Phishing attacks in particular. Though I guess the extra clicks should discourage users.
1 comments

It is necessary — some places have custom non-public CA's, for things like S/MIME and internal servers.

On the other hand, I'm pretty sure Siri doesn't have to communicate with your company's internal servers (and my paranoia already suggests a malicious IT department, reckless — and probably illegal — as that would be), so the code should, in my opinion, accept only specific CAs.

Compartmentalization would make sense. Installing a root CA in the email app would only work for the email app.