My concern is basically that this forces people to use very expensive cert providers, since in feasible to setup and connect and secure an HSM that can do this yourself. And Microsoft and Amazon have tricked the browser forums that their online ones are good enough.
It essentially puts yet another monopoly into the “open” Web. The CA browser forum is a joke at this point and I don’t respect any of the decision in the last 10 years. They all serve to further centralize and close off the web.
People keep bringing up LetsEncrypt, but it very much cannot issue EV carts. It costs THOUSANDS of dollars to use a service that can auto renew “trusted certs”.
SoftestSapphic@lemmy.world 11 months ago
Can we stop doing certs now?
Can we stop letting google decide what is and isn’t acceptable on the internet based on who gave them money?
pogmommy@lemmy.ml 11 months ago
Miserable bait
JackbyDev@programming.dev 11 months ago
Certs are free through Let’s Encrypt (and have been for quite some time now, like a decade). Certs makes people peeking at what you’re doing along the route substantially more difficult.
bane_killgrind@slrpnk.net 11 months ago
So how do we do trust if we don’t have specific people to trust to issue trust
SoftestSapphic@lemmy.world 11 months ago
Just go to the website.