|
|
|
|
|
by dextercd
431 days ago
|
|
I think most orgs can get away with free ACME clients and free/cheap monitoring options. This will be painful for people in the short term, but in the long term I believe it will make things more automated, more secure, and less fragile. Browsers are the ones pushing for this change. They wouldn't do it if they thought it would cause people to see more expired certificate warnings. > Unfortunately the CA/B is essentially unchecked power, no individual corporate member is going to fire their representatives for this, much less is there a way to remove everyone that made this incredibly harmful decision. Representatives are not voting against the wishes/instructions of their employer. |
|
Unfortunately the problem is likely too removed from understanding for employers to care. Google and Microsoft do not realize how damaging the CA/B is, and probably take the word of their CA/B representatives that the choices that they are making are necessary and good.
I doubt Satya Nadella even knows what the CA/B is, much less that he pays an employee full-time to directly #### over his entire customer base and that this employee has nearly god-level control over the Internet. I have yet to see an announcement from the CA/B that represented a competent decision that reflected the reality of the security industry and business needs, and yet... nobody can get in trouble for it!