Hacker News new | ask | show | jobs
by LaGrange 5329 days ago
It is necessary — some places have custom non-public CA's, for things like S/MIME and internal servers.

On the other hand, I'm pretty sure Siri doesn't have to communicate with your company's internal servers (and my paranoia already suggests a malicious IT department, reckless — and probably illegal — as that would be), so the code should, in my opinion, accept only specific CAs.

1 comments

Compartmentalization would make sense. Installing a root CA in the email app would only work for the email app.