--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/6f09f6f3-16d8-44c6-ad34-470a234407acn%40mozilla.org.
>Are you suggesting that WebPKI encourages large monopolies?
Absolutely, but it actually does more than that, the high barriers to entry
and high cost to remain have three effects:
1. Only large monopoly CAs tend to prosper (government- and corporate-backed
vanity CAs with independent funding are another matter, but then they only
issue vanity certs so barely count).
2. Everyone becomes a reseller for a CA (with minimal controls and checks and
balances) rather than a full CA (with audits and checks and balances).
3. Because of this there's an impenetrable mass of cross-certifications of
sub-CAs that make it more or less impossible to determine whether you've ever
managed to knock out a rogue player.
In effect the Web PKI selects for the worst possible type of PKI.
Peter.
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/a93695d0-d3a0-45a8-af55-7cbe0a81fd8dn%40mozilla.org.
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CAMm%2BLwhf1wt8Dy7fh6zcLRrNzu_VrCai88_zVEpFOgyfFjSEyw%40mail.gmail.com.
--
You received this message because you are subscribed to the Google Groups "dev-secur...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dev-security-po...@mozilla.org.
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/ca173ea8-f2c7-45c5-bc41-d107048cb4bcn%40mozilla.org.