Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Doesn't this just shift the exact same trust to registrars?


It shifts the trust to a single CA instead of all the CAs.


More precicely, it means that compromising the public key infrastructure requires compromising one specific CA, rather than compromising any single CA out of hundreds. Ideally, we would it to instead require compromising all CAs out of hundreds, but as long as the defective-by-design X.509 PKI is used, that's not very possible, much less likely.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: