Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fine, stop using them. You still trust them. Your visitors browsers still trust them. Being paranoid wrt a Chinese CA really makes no sense. They have as much incentive as a western CA to behave wrt keeping their signing keys secure, and their revocation list sensible, which is all that really matters.


People need to read this.

There are many things to take into account when choosing a CA to use for your site. But security, jurisdiction and any history of mis-issuance are not relevant to you; only reliers. And no relier has any choice in the matter anyway, or any economic relationship they can terminate.

(Things change if you start to use HPKP and pin to a particular root; nobody does that though because it's an availability and economic nightmare.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: