- A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.
- A US Government controlled CA root preinstalled on computers. Privacy advocates would be in arms. - Constant untrusted CA warnings when trying to access any government site.
This is how dn42 does it: https://dn42.dev/services/Certificate-Authority.md
Regardless, this puts you back at a US Government controlled CA being on your machine.
Do you really trust the turkish government with the ability to sign for any domain.
Some days I consider tearing out the whole thing and rebuilding with the 3 CA's I actually care about. but then I usually give up as too much hassle.
Annoyingly, it doesn't have my country's national CA hierarchy (https://bugzilla.mozilla.org/show_bug.cgi?id=438825).
Why is it annoying? Because it means you have to add it manually, and manually added root certificates have more power than the root certificates that come with the browser! In particular, they can bypass HPKP (security.cert_pinning.enforcement_level defaults to 1).
No, but I don’t have to. To be included in the root CA list, they have to participate in cert transparency logging. So I can just pick a log to monitor, and check to make sure they haven’t issued a cert for one of my domains.
edit: I just read the spec. the cert needs to be logged to be considered valid by the browser. which has fun connotations where google is effectively monitoring everything you access. basically the mother of all analytics. well... I mean... that is.. if they were not already monitoring everything you do on the web. so it's ok I guess.
Before Certificate Transparency, I'm pretty sure they already could do that relatively easily by forcing a private CA to make them a cert. (National Security Letters and all that fun)
Even now, with CT, I think they'd be more inclined to use a private or at least an "unofficial" CA, instead of basically leaving "your's truly, The Government" in the CT log. If you already know you'll leave a trace, why would you want to make that trace extra obvious?
Which is a problem with the root cA design.