Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While I agree with you about pulling the rug out from users - if the CA is already forging certificates for important domains, then how much security do they really have?


More than they do if the whole CA is removed. Sorry, annoying but true. Promote TACK!


right now only the turkish government can do MITM - other parties can't.


> right now only the turkish government can do MITM - other parties can't.

First, if true that's a small comfort. Second, how do you know that is true?


It's in the Turkish government's to use these invalid certs as little as possible, so they are probably going to use them against people like Turkish dissidents.

(I don't mean to dismiss their interests, but they are distinct from other people's interests.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: