So yes shipping a CA known to have intentionally issued false certificates is very on-brand for them.
So yes shipping a CA known to have intentionally issued false certificates is very on-brand for them.
Did TrustCor turn out to have done that? The last time I checked in on that, the distrust was mainly founded on some not-very-trustworthy behavior involving spyware in a related company within the same corporate umbrella.
EDIT: Link to the rationale for distrust from Mozilla ... https://groups.google.com/a/mozilla.org/g/dev-security-polic...
excerpt: "There is no evidence of TrustCor mis-issuing TLS or SMIME certificates."
TrustCor met this requirement and got removed.
Other CAs removed in the past also showed they are unworthy of trust, but in even more blatant ways.
Trustcor allegedly spread spyware, which I do think makes anyone untrustworthy. But it should be checked if allegations can be confirmed.
I haven't heard that before. Care to elaborate what we do that makes you believe we don't take security seriously?
As for engineering decisions, let's just say better stick with debian on anything non-desktop.
Love it for my servers but it is not very convenient for the desktop.
I don't think it's as bad as most people think it is, nowadays.
That is the big feature of Ubuntu for me. Can set in my calendar when it's time to migrate services to the next version.