Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Without the root cert installed, they add zero additional security, because the browser can't verify them. They might as well be self-signed.

CACert has been working on this for a long time, and the outlook does not seem positive. If they can't even get past Mozilla's audit requirements, how well do you think they'll fare with Microsoft?



I checked in with someone from CACert at 26C3. As far as he knows, the audit is moving forward and they expect to make it into both.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: