Slowly ostracising and forcing "compliance" of those who don't toe the line is easier than before. They want you to be obedient sheep, living in an illusion of security and safety while continuing to mindlessly consume under their control.
I will resist the urge to post that memorable Franklin quote.
* ads on page
* seeing all internet traffic to enhance targeting
The real conspiracy would be to know a better system and not tell anyone. Which is like sponsoring scientific discoveries and then hiding those behind a pay wall. Oh wait again.
What do you mean "listen"? CAs can invalidate certs at will, but, they have no mechanism to listen on communications (unless you give them your private key, but, then anyone you give your private key to can eavesdrop).
The CA system has lots of issues. It would be a pretty big conspiracy if there were thousands of people that knew of something better and said nothing. But, there is absolutely no proof that anyone has any idea how to do better than the CA system. Do you know of such a system or have any evidence that someone else does? Google, despite their flaws w.r.t. privacy, has done quite a bit of work to improve the CA situation - Certificate Transparency, for example.
A court seizing a domain thereby invalidating a cert.
> What do you mean "listen"?
If I accept a custom cert, but don't validate the key, I might as well use none, basically. That's the extent of my knowledge, I don't know what Certificate Transparency is doing, for example.
> The CA system has lots of issues. It would be a pretty big conspiracy if there were thousands of people that knew of something better and said nothing. But, there is absolutely no proof that anyone has any idea how to do better than the CA system. Do you know of such a system or have any evidence that someone else does?
> It would be a pretty big conspiracy
Exactly, so why do you expect that twitter sized post could it explain it convincingly?
> if there were thousands of people that knew of something better and said nothing
Ironically, it might be the ability to censor communication to suppress such voices, however hypothetical that is, that triggered the GP.
> But, there is absolutely no proof that anyone has any idea how to do better than the CA system.
PGP is used with key exchange in real live. I'm not using it, just arguing for the sake of the argument. It has problems, too, but "better" is not a binary value , except in the limited scope of the specific problem. PGP doesn't need root CAs.
Plus, they won't remove the functionality to manually trust a cert (Business Users would complain).
Firefox has implemented the same rules around .dev tld's as google. I use vivaldi when accessing internal company .dev domains because firefox won't let me tell it to accept the self-signed certificate.
Well, another argument in favor of not overloading TLDs for internal domains, then, and just buying an additional domain if you really want to have separate internal and external domains.