|
|
|
|
|
by mikeash
4105 days ago
|
|
CAs aren't geographically limited. Any CA trusted by your computer is trusted for any domain anywhere (with the exception of certificate pinning, which isn't commonly used). That means that a single rogue CA is enough to make HTTPS worthless everywhere. |
|
https://wiki.mozilla.org/CA:IncludedCAs