Root CAs [was Re: Upgrade 8.2 -> 9.4 breaks cpan?]

Mouse <[email protected]> Mon, 18 Nov 2024 17:58:52 -0500 (EST)
Newsgroups gmane.os.netbsd.ports.macppc,gmane.os.netbsd.general
Message-ID <[email protected]>
> Root C(ertificate)A(uthorities) are a failure and acts of oppression

I don't think they're a failure per se.  They do what they're designed
to do very well.  Trouble is, it's what the designers want(ed), not
what you (or I) want(ed).

CA-hierarchy-secured communication is a fail for me because it is
completely unable to protect against the actors I am most concerned
about, which are large corporations and governments: the ones who are
the roots of the (so-called) trust hierarchy, the kind of entity which
can easily get certs for *.com and the like.

It's putting the foxes in charge of securing the doors on the henhouse.

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		[email protected]
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B