Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your browser, or trusted cert provider, should just have a clear policy that once trust is broken, according to well defined rules, the cert is auto-revoked with no appeal. Then it is only a matter of executing the policy, not an ex post facto political game.

If your trusted source does not have such a policy, drop them.



Do you have any suggestions about where to look for such a "trusted source"?

I fear my comfortable life with iOS/Android/OSX/Windows/mainstram-Linux OSen at my bidding in various devices and niches, would need to change radically to approach that ideal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: