|
|
|
|
|
by throwaway5435
4004 days ago
|
|
The Microsoft Root CA cert is not included in the NSS trust store.
This would break Windows Update (something that Samsung has recently been accused of breaking).
So you have to trust the Microsoft CA Root Cert;
And if you trust that, you trust they won' sign a SubCA cert, which they could do. If you don't trust your trust provider, don't use their software? |
|
I'm also fine with them signing for outlook.com, microsoft.com etc.
I'm not fine with them signing for wikileaks -- but I also am not really worried about that. I'm worried that some fly-by-night CA will loose their keys, get hacked, etc. So I don't want any more than a minimum of CAs on my system, and I'd like to approve them on a domain-by-domain basis.
Even with good UX, that'd bee way more hassle than most people want -- I know that. But it would've been nice to have a sane option for it.
And also some special control over updates/upgrades to the CA-cert store.
In short, I trust Microsoft to write software, I don't trust them to delegate trust, because they're trapped in the CA racket.