38 points | 14h ago | Discuss on Hacker News | Back to Radar
Now, if you want to play with the world at large that's been dealing with security issue after security issue then you play by those rules.
You can't come to my game then get mad when I have a set of rules you don't like.
The CA/B is the embodiment of the phrase "if all you have is a hammer, everything looks like a nail".
In aggregate this is a very good thing
They usually grow enormous bureaucratic theatre around long-lived cert renewal, leaving them unable to do rapid rotation when it is required. And rather than getting their shit together, they prefer suing their CA to avoid revocation.
Given that those organisations 1) are crucial for day-to-day life (like banks, or the government), and 2) would have a giant blast radius when their certs are compromised, and 3) won't voluntarily change, the only remaining option to keep the ecosystem healthy is to force them by making complex rotation processes extremely painful and cumbersome to keep.
Hence: automated renewal, and boil the frog by slowly lowering the validity period.
Comments are loaded live from Hacker News and are not stored by Mid or Real.
bombcar 4h ago on HN
Towaway69 3h ago on HN
/s
crote 52m ago on HN