Re: Draft finding - "Transitioning the Web to HTTPS"
Marc Fawzi <[email protected]>
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CACioZiukToOkx5djkT5mW7AZF0thxbAt7wWnKK2kMbyecXrirQ@mail.gmail.com> |
in case some missed this: http://blogs.msdn.com/b/ie/archive/2015/02/16/http-strict-transport-security-comes-to-internet-explorer.aspx On Tue, Jan 20, 2015 at 4:49 AM, Anne van Kesteren <[email protected]> wrote: > On Tue, Jan 20, 2015 at 1:28 PM, <[email protected]> wrote: > > 19.01.2015, 15:01, "Anne van Kesteren" <[email protected]>: > >> Anything but proper CA certificates is a major attack vector > > > > This is misleading. "proper CA certificates" is a very ill-defined term. > > It seems you missed the earlier email where I established that > non-user installed CAs are vetted. And that as far as Gecko goes (and > I believe Chromium uses a derivative) there's a public vetting process > for CAs: https://wiki.mozilla.org/CA That process is quite well > defined and has seen over a decade of practice. > > > -- > https://annevankesteren.nl/ > >