Hacker News new | ask | show | jobs
by bulbar 20 days ago
On infrastructure level, let me as a user (easily) decide which Root CAs I want to trust. Have websites by default deliver certs that match my region (i.e. a cert from a European Root CA if I'm in Europe).

By itself, this won't do anything (because you will still be using service that utilize US servers, but will be an important step for the safety of the non-US world.

I guess it will be other way round. More services will be run independent of the US and this will result in pressure to also solve the cert issue.