Back to News
Advertisement
Advertisement

⚑ Community Insights

Discussion Sentiment

0% Positive

Analyzed from 196 words in the discussion.

Trending Topics

#certificates#root#tld#cert#cross#internet#point#whole#working#operators

Discussion (6 Comments)Read Original on HackerNews

m463β€’3 minutes ago
Just say no. Cloudflare should not be the gatekeeper for the internet.
m4rtinkβ€’30 minutes ago
Totally not a single point of failure for the whole Internet.
phillipseamoreβ€’about 2 hours ago
Would like to see them working more with TLD operators here, I'd like to see a CA partner with TLD ops to offer distributed and resilient issuance (especially with shorter cert lifetimes) with intermediate certificates locked to their TLDs, TLD operators are already a significant part of the chain of trust since it's all based on DNS today.
MisterMunchkinβ€’about 5 hours ago
It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
evan_a_aβ€’21 minutes ago
There are a whole host of controls in place to mitigate this risk. Plus such an acquisition wouldn't be easy to keep secret, so as soon as an untrusted actor acquired control over a root, the CAB would likely immediately distrust the cert.

https://cabforum.org/working-groups/server/baseline-requirem...

phillipseamoreβ€’about 2 hours ago
Not a huge difference between buying the root cert itself and getting a cross-sign. LE started out with cross-signs from Identrust.

"On October 19, 2015, the intermediate certificates became cross-signed by IdenTrust, causing all certificates issued by Let's Encrypt to be trusted by all major browsers."