The industry is moving forward and doing lots to improve.
Lets also not forget a hugely important point that there is no evidence of harm from Symantec's action. They were just embarrassingly stupid and irresponsible.
The industry is moving forward and doing lots to improve.
Lets also not forget a hugely important point that there is no evidence of harm from Symantec's action. They were just embarrassingly stupid and irresponsible.
I dont think the CA system is unique in having breaches, holes, or incompetent actors.
It's also unique is that when an authority has a hole, breach or is an incompetent actor, it's very difficult to remove them from authority.
There is no proof of this. There are lots of systems in place to deal with mistakes and trust breaches. If it gets to the extent that a Root or CA needs to be removed from trust stores, then they are removed.
Just this year we saw two CAs lose their trust.
I think the last too-big-to-fail CA that misissued certs in recent memory was Comodo, in March 2011, who had a reseller's account broken into (apparently by an Iranian state-sponsored attacker). And that was well before there were options like insisting on Certificate Transparency, and Comodo reacted well (they had an accurate audit trail and deployed changes that blocked the attacker when they retried two weeks later), and it didn't involve active incompetence on Comodo's part. Since then, there's also been CNNIC, India CCA, TURKTRUST, ANSSI, and DigiNotar. CNNIC and DigiNotar have both been removed from Chrome's root store, India CCA and ANSSI have been restricted to their country's TLDs, and TURKTRUST (which apparently reacted well) lost their EV powers.
(There were also a couple of misissued certs due to Microsoft Live allowing anyone to sign up for accounts like "hostmaster", but those are not considered the CA's fault.)