|
|
|
|
|
by jesboat
1278 days ago
|
|
The privately run industry is maybe a tiny bit better, but that's not the point. The point is that the only way browsers have to influence a CA or the industry is the threat to eventually distrust. If they can't threaten that to government-stamped CAs, then those CAs no longer even have an incentive to operate responsibly, and, as we know from the many, many incidents, they almost certainly won't. |
|
If I had to guess, half of the least trustworthy CAs in the one-store-fits-all keystore are also government affiliated ones and we don't even get anything to differentiate them from any regular commercial cert.