Also, I think you have to manually confirm as a user to install such certificates.
Maybe I am missing something, but this smells like "Korea Bad" without explaining why.
Also, I think you have to manually confirm as a user to install such certificates.
Maybe I am missing something, but this smells like "Korea Bad" without explaining why.
In fact, the article does explain this. The CAs that are on this list by default have to comply with strict criteria making sure they cannot be abused. Anything that has been added externally, avoiding the usual processes of Microsoft/Mozilla/Apple, is suspect.
There's no authority above root certificates,* able to sign new certificates - that's what it means to be a root certificate. So root certificates will often have super long durations.
For example, the certificate HN uses is signed by "DigiCert Global Root CA" - valid from 2006 to 2031.
* Unless you count the power of OSes/browsers to push updates with new certificates.
No...? They mean that if a piece of third-party software adds its own CA (see Superfish) then it's automatically suspect.
-Emily