Re: Considering the pressure to turn HTTPS into a three-party protocol

Ryan Sleevi <[email protected]>
Newsgroups gmane.org.w3c.tag
Message-ID <CACvaWvahQNBJU2LhZXocEh1qLh7RjrKPqmsXLc_W2yzrsRqB_Q@mail.gmail.com>
On Sun, Feb 15, 2015 at 6:30 PM, Mark Nottingham <[email protected]> wrote:

> CA certs and extensions are built into all of the major browsers.

This is demonstrably not true.

Chrome (on most platforms), Opera (post-Blink) IE, Safari, and Firefox
(as packaged by every major Linux distro, but not as distributed by
Mozilla) all treat CA certificates as part of the OS/operating
environment, much in the same way that name resolution is.

Of those that distribute certs in-band, this is only Firefox (as
distributed by Mozilla) and Opera (prior to Blink).

I realize I'm ignoring a large swathe of UAs in that mix, but I think
if we're going to use terms like "all major browsers", then it's worth
noting how incorrect this statement is.

> Because this is a question of how the Web is presented to and understood by end users,

Having the W3C issue findings on how the Web presents security indica
has historically gone over like a lead balloon (c.f.
http://www.w3.org/TR/wsc-ui/ )
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.