126 karma · joined May 12, 2017
I think I've observed enough of this sentiment over the years, from some very smart and successful people, to come to the conclusion that, if it is nonsense, it is non-obvious.
> I never diminish anyone
Perhaps you never _intend_ to diminish anyone, but to some, your statements may reasonably appear to be diminishing some cohort.
What does the perverse scenario look like for you?
https://www.eff.org/deeplinks/2017/07/amid-unprecedented-con...
https://www.defectivebydesign.org/blog/w3c_sells_out_web_eme...
From olau's explanation, it seems that there is enough money flowing, that more than 80% can be financed (in some way) even if it is not in a single or collateral-backed loan.
The thing is, you need this equivalently for any cloud provider as well. People who know how to operate and run a cloud account effectively are not a dime a dozen, and given the migration going on now are actually in higher demand than some qualified datacenter operators.
By the same token, if that web host were hacked and used to obtain a nefarious certificate, would the CA be accountable? It seems to me that, as a customer, if you point your domain (which you must do somehow) at a hosting provider, then any DV issued with that hosting providers' infrastructure should be considered to be the responsibility of the hosting provider and domain owner. I think you and rgbrenner are making perfectly valid points for high-value infrastructure, which has in my view very little to do with these hosting providers. The fact that people can upload certificates at all for domains which they have not proved (to the hosting provider) ownership of is disturbing in and of itself, even if it is quite common.
I think you underestimate the capabilities of modern infosec tooling. Essentially the whole of the internet can be scanned in some ways in durations measured in hours. What is more, some systems are being constantly updated (such a certificate transparency), and there are relatively easy ways to identify bad actors via whitelists and behavioral monitoring. All that being said, if you have a legitimately better idea, voice it in a meaningful way, and I am sure they will at least listen. That was the part _in_their_post_ about "taking community feedback" you must have missed.
[1]https://coreos.com/rkt/docs/latest/running-kvm-stage1.html
They say "It has been four years and we still have to use Dockerfile, which is a horrible version of bash." They say "we still have to use Dockerfile". They _never_ _had_ to use Dockerfile.