TBF Cory just riffed off the ZDNet headline.
"Google guillotine falls on certificate authorities WoSign, StartCom"
Unless Charlie Osborne meant that they’d be amputating a limb. Or going for a really avant-garde hair-cutting approach. One never knows for certain.


Do people actually leave any Chinese cert authorities enabled ? ( Or god forbid the Hong Kong post office)


Yes. The ‘tyranny of the default’ indicates that everyone leaves everything on that’s on by default.

If you asked most people if they allowed the certs from the Hong Kong post office enabled, their answer would most likely be “the what from the who?”


Those rogue CAs richly deserved it.

On the other hand, Symantec (and previously COMODO) got a mere slap on the wrist for offenses just as serious, because they are too big to fail. If Chrome were to reject Symantex certs, about 1/3 to half of all websites would stop working and people would switch to Firefox or Edge. This puts them (and other browser makers) in a bind and you can just feel the frustration from the likes of Ryan Sleevi at Google.

Unless the browser makers agree to coordinated bans along with some way to notify webmasters so they replace their certs ahead of time, scumbag companies like Symantec will continue to abuse their certificate-issuing with near impunity.


You know, I consider myself to be computer savvy yet it’s never occurred to me to disable a specific CA. Nor that I even could. Or know where to learn what CAs I should doable.


I like the neologism, “doable” as an antonym for “disable”.


