Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

WoSign/StartCom got a bit of a smackdown about their stealth acquisition so there is some level of oversight.


Only because they made the mistake of sharing their infrastructure (hence, their quirks) and got caught. I wouldn't call that oversight.

CAs should be required to announce ownership or large administration changes, and trust in said CAs should be revoked upon change unless/until they have been re-audited.


That is effectively how both the Mozilla and Microsoft programs root store programs works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: