Hacker News new | past | comments | ask | show | jobs | submit login

TL;DR Google prefers to override what the standards say about validity of certicates instead of what would be the logical thing: stop trusting Symantec root Certs. A dangerous precedent.



Google is divesting trust from Symantec but is doing it in a way that avoids hurting end-users and badly breaking the internet. They explicitly state why they don't just want to revoke it in one go and they have really decent arguments. What are yours?

Aside from that, to the best of my knowledge the CA/B forum doesn't set forth any rules that require the immediate and complete removal of trust of a CA that is found to be in violation of the guidelines. I also don't see how they could, the best they could do is put out some form of recommendation but it's up to the parties that actually include the CAs to decide how they get removed, which is normally stipulated in the rules for inclusion in a Root Certificate bundle.


Can you elaborate? Having trouble parsing whether you think Google is over- or under-reacting.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: