56 karma · joined June 15, 2012
Well, the technology is there and works as advertised. It is just getting people to adopt, and since people depend on hosting companies hosting companies need to upgrade. That hasn't happened. Ever. But it is not the failure of email, I would say, but a failure of the internet ecosystem that is incapable of upgrading itself because of its fragmentation.
Surely, moving to another service provider is fully legit. However, a hijack with a rogue certificate (say from an undiscovered Diginotar) would not be visible to users - thereby exposing their credentials. So people use TOFU (trust on first use) mechanisms like Certificate Patrol:
http://staff.science.uva.nl/~delaat/rp/2012-2013/p56/present...
The future is of course DANE with DNSSEC, where you put information about the certificate and/or the CA in the DNS.
"Browsers trust a very large number of these CAs, and unfortunately, the security of HTTPS is only as strong as the practices of the least trustworthy/competent CA. Before publishing this data, we attempted to notify administrators of all sites observed vulnerable to the Debian weak key bug; please let us know if your analysis reveals other classes of vulnerabilities so that we can notify affected parties."