Hacker News new | ask | show | jobs
by hyperman1 963 days ago
Https always had problems with the long list of mysterious root certificates. Maybe this is the push needed to do something about it, e.g. :

* Warn when a new root is user for the first time.

* Warn when a site changes its root cert.

* Warn when a root cert is used for DNS names that shouldnt belong to it, e.g. wrong tld.

In a broader context, the question who you trust when will become more and more important. E.g. deepfakes might push us all to digitally sign their real messages. I don't think the current root certificate systems can survive the deluge of mistrust generated by AI.