Hacker News new | ask | show | jobs
by sk5t 4763 days ago
A hostile entity owning the public CAs doesn't render "any" encryption useless--just PKI that trusts those common CAs. We could revert to the PGP signing parties of the 90s, or a variety of other key exchange protocols... just no more relying on a certificate because Thawte, Verisign, or (ha!) Comodo say it's good.