Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What about a crowd-sourced decentralized list of known bad-CAs or certificates known to be used by Government security services? At the very worst, it will raise some warnings and let the user think twice before connecting to that service (which may or may not be annoying), but at best it would shield users from surveillance?


The government and corporations (and thus defense contractors) are experts at manipulating crowdsourcing for their own ends. I sure as hell wouldn't trust crowdsourcing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: