Hacker News new | ask | show | jobs
by pushrax 4101 days ago
While a step in the right direction for EuroDNS, it's not really exciting at all. We need more completely free CAs.
1 comments

No, we don't. The CA is supposed to verify the owner of the certificate and stand behind that with a financial guarantee. Otherwise, it's just security theater.
I'm getting certificates for various websites with fake details for years now. The theater is there already, it would and we should not pay for it anyway.
Please post bad certs on "dev-security-policy@lists.mozilla.org". They can be revoked. Mozilla is introducing a Mozilla-controlled revocation list in Firefox 37.

There's a lot going on to tighten up the CA world.

The whole CA system is already a security theatre.