Yeah, fuck that. Like hell am I going to use a free CA as suggested. They have no incentive to keep things secure or in working order at all.
Great article otherwise though!
Yeah, fuck that. Like hell am I going to use a free CA as suggested. They have no incentive to keep things secure or in working order at all.
Great article otherwise though!
"The hackers behind the attack on StartCom failed to obtain any certificates that would allow them to spoof websites in a similar fashion, and they were also unsuccessful in generating an intermediate certificate that would allow them to act as their own certificate authority, Nigg said in an email."
As opposed to the Comodo breach where the attackers successfully managed to get fake certificates for several high-profile sites.
They have just as much incentive to secure their systems as any other CA. Their reputation is just as important to them.
It doesn't matter which CA you use. If your CA, or any other trusted CA is compromised, you're affected exactly the same.