Hacker News new | ask | show | jobs
by 0xbadcafebee 22 days ago
They control the OS and the Browser, the two things that specify what CA certs can be validated and how. CAs can disagree all they want, but they can't do anything about it. The big 3 don't want to be in the CA business, so they haggle over rules, but it's not a level playing field
1 comments

Oh, I agree about their market power, just saying CAB is complicated.