|
|
|
|
|
by e12e
4003 days ago
|
|
I trust MS software. I don't trust MS to select which CA to trust. Sure, MS could backdoor my os/browser. I don't think that's very likely. If MS force me to trust, say 800 CA certs, and all of them can mitm wikileaks, the likelihood that one of them could be penetrated by a hacker or a state actor is much higher. Sure, it's not "absolute security", but nothing is. There are different concept that one trusts, or not trust: The os, drivers, bios, hardware. I generally trust that. It may be naive, but I do. However, even if I'm right in trusting that, that doesn't matter if I can't trust all the CAs. Not just from the point of malicious actions by the CAs, but from incompetence by them. |
|