Hacker News new | past | comments | ask | show | jobs | submit login

Trust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.



Mozilla has identified issues with CAs that are part of eIDAS. The severity of these issues can be debated, but the nice part of Mozilla's root program is that these are publicly debated. For example, the community identified repeated issues with the CA Certinomis and after failures to improve they were distrusted. Is it a good thing that the EU says that doesn't matter and Certinomis certs must be trusted as part of eIDAS?

https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...

https://wiki.mozilla.org/CA/Certinomis_Issues


Mozilla argues in their paper that once governments in one part of the world start forcing browsers include root certificates, governments in other parts of the world will start doing the same shortly after. You might trust your government more, but you certainly wouldn't trust arbitrary governments more.

Furthermore, I have seen nothing wrong in mozilla's stewardship of the root certificate program in the decades it's been running, whereas mozilla points to deficiencies in the EU's certificate programs. This is to be expected since running a root store is not one of the EU's specialties. I would trust that government most that defers to private companies in areas where they lack expertise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: