7 ms·
For those looking for more context - If memory serves it was in response to https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Certificate_hacking https://en.wi
by resonanttoe 2y ago
For those looking for more context - If memory serves it was in response to https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Certificate_hacking https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Certifica... and the various controversies around it.
Honest Achmed has been one of my favorites for as long as its been around.
- fmajid 2y agoAnd also Symantec, and now Entrust. All of these CAs have incredibly sloppy vetting procedures and/or control over their resellers. In many cases they didn't even check CAA records to see if they'd be authorized to issue new certs, even though it has been a requirement for years. They had one job, and failed abysmally at it, relying on their too big to fail status. You can feel the frustration of people like Adam Langley at Google over his inability to bring the banhammer to bear fast enough on those clowns.