‹ BackHN Continuity

Thread

Building a certificate authority for the whole Internet

73 points · 57 comments · ewpratten

  1. MisterMunchkin · · focus · HN ↗
    It makes sense for them to issue their own certificates because it’s inline with the rest of their offerings, but it seems kind of strange you can just buy someone else’s root certificate and issue under their name. It kind of defeats the point of trusting the root. What if a bad actor starting buying up authorities? You could compromise a bunch of services without them even knowing.
    1. vg · · focus · HN ↗
      Google (GTS) has done the same. GTS controls GlobalSign R4. GlobalSign R4 was a root cert which was created by GlobalSign and later sold to Google.

      If a bad actor starts buying up CA's, then very quickly that CA would be distrusted by Root Cert Store Operators. No different than what happened with DigiNotr and Entrust.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.