Bonum Certa Men Certa

Transport Layer Security (TLS) is Fine, Centralised Certificate Authorities (CAs) Are Not

Video download link | md5sum b147528fd1ea28881ed4578632fbd8b7 War on Decentralised Internet and Computing Creative Commons Attribution-No Derivative Works 4.0



Summary: There's a lot of misconception/misunderstandings about what the Certificate Authorities (CAs) are, what they're for, how they work, and why they don't actually tackle the biggest security and privacy problems, they're mostly about centralisation of control and outsourcing of "trust" from pertinent sites/services to monopolies, empires, and oligarchs

SOME days ago someone was "[s]houting out to @tuxmachines to check your server. SSL certificate-based error messages are flying..."



This was not unforeseen. A lot of people sadly believe what Web browsers tell them, not bothering to take into account the agenda promoted by such Web browsers. It's about control and centralisation, it's not about security and/or privacy. A "malicious Web site can easily get a TLS certificate from a CA and turn the padlock on your browser green and go ahead and load," DaemonFC reminds us. "And it's still a malicious Web site."

"Let's Encrypt even admits that they do nothing to protect you from a malicious Web site, and suggest reporting those to Google and Microsoft," DaemonFC adds.

"A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia."Those who say that getting a 'good' certificate is 'free' may be missing the point. It is like buying a 'secure' boot certificate from Microsoft on the 'cheap' (until the OEMs toss them out). We wrote about this in relation to Certificate Authorities before, with focus on the "big fish", Let's Encrypt [1, 2, 3], or LE.

The video above revisits this subject. A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia. Now that the centralised systems are in place, censorship is vastly stronger. Is this security???

A given Gemini address is accessible so long as there's a certificate in place, even a self-signed one (vouching for oneself). The same model ought to have been adopted for the Web. For online banking it would help if banks sent expected fingerprints, e.g. by post. Outsourcing to monopolies isn't the way to go.

"Outsourcing to monopolies isn't the way to go."Readers might correctly spot the resemblance or notice the similarity to UEFI 'secure' boot. First they start with recommendations, saying it is all about security and enhancing safety. And then intimidation, seeking compliance from people who disregard the recommendations. Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered. So this is a form of blackmail for lock-down, initially marketed as a well-meaning security scheme. They're insincere about motives. Nothing here is "free"...

Right now, after we've witnessed expansion in Web censorship, we believe stronger resistance will be needed by explaining to people what's happening. Remember that this is not about security; it's all about control and one day revoking certificates can be weaponised further and further, just like DNS-level censorship, denial of ClownFlare access, and so on. They typically start with "pirates", "terrorism", and "the children" before resorting to political angles. CAs can very easily and immediately be leveraged for outright censorship.

"Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered."In the video above I remind people that the Linux Foundation's LE has already revoked millions of cerificates before (without even properly explaining what had happened!) and it'll happen again sooner or later. Maybe at some point they'll just decide to revoke all LE certificates for Russian sites, citing some political "sanctions". Then what? Who's next?

As an associate noted yesterday, "those that control the signing authorities can issue revocations at any time they feel like it and for any reason they feel like..."

In the case of Debian, we recently saw how trademarks get leveraged to censor criticism and hide problems. They just confiscate critics' Web sites. Maybe we'll do a video about this soon, seeing that the debian.community site is now succeeded by debian.day and debian.news. It's a namespace battle in DNS.

DaemonFC concludes: "The only thing that HTTPS does do is help keep what you do to interact with the server private from outsiders, and that is important. But if you fall for a site claiming to be your bank because it has a green padlock, that doesn't help you avoid a scam. One of the reasons I used to promote HTTPS Everywhere to everyone was because I believed the user should have the option to try to force it on with as many sites as possible. But I never would have argued for a system where HTTP is basically deprecated without TLS and browsers try to say there's something wrong with accessing such a Web site if you don't mind your information between your browser and that site remaining private. It's a good "upgrade". It is. It stops things like the Man-In-The-Middle Attacks that Comcast was using in order to spam its customers and inject advertisements into Web pages. So that's why I started using it. I thought it was outrageous that wherever I went, here's Comcast injecting alerts about data usage or ads for their TV package into my Google searches. HTTPS breaking that is a happy side-effect of what it does."

"I was big on the idea of bringing CACert into the certificates package used by Mozilla, but they always found some bullshit reason not to. Like, they didn't even want to talk about it. The whole situation with certificates is a legacy of Netscape. All of the old "players" that are really valuable and "trusted" by just about everything started out that way because Netscape Corporation put them in the Netscape Navigator browser. Then Microsoft came along with their stolen Internet Explorer product (they stiffed Spyglass Mosaic and then didn't pay them) and lobbed all the same certificates in so that sites working in Netscape Navigator would also load in Internet Explorer. And then the tragedy just kept expanding from there. Opera had to throw all the same certificates in because they've never had more than 2% of the browser market. The user has really no control over how this works. It's always been 100% Big Business. From Netscape to Microsoft to Apple and Google."

"Remember when they had that Diginotar CA that was compromised? An entire CA! They had to revoke and remove an entire CA. What a mess that was. Everything in that "chain of trust" was broken and all the sites that used it had to get new certificates, and many Windows and Mac developers got caught with their pants down and had security alerts warning the users not to install the software that the OS was saying "THIS IS FINE!" about yesterday. That was hilarious, and sad. Sad because everyone watched what ensued and nothing was fixed. They revoked one CA and caused all sorts of Hell, but it could happen with any of them."

They still push this very same agenda for software, not only Web sites, various services (including IRC), and booting.

MinceR then said that "PKI as a whole is badly designed."

Recent Techrights' Posts

Google "AI" is Plagiarism, the Case of Richard Stallman (RMS)
Why would anyone choose LLM slop over the originals, curated and fact-checked by domain experts?
SLAPP Censorship - Part 136 Out of 200: Lawyers That Get Paid to Mess About
They were already outnumbered and understaffed
Explaining That Software Patents Are Neither Legal Nor Desirable
Many of our readers work in the legal sector
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 31, 2026
IRC logs for Friday, July 31, 2026
Gemini Links 01/08/2026: Retirement, Bike Trips, Quake Stuff, Usenet Reborn
Links for the day
Links 31/07/2026: Microsoft Now Says Slop is Bad (LinkedIn Cracks Down on It), LinkedIn Narrows Down Size (No Expansion)
Links for the day
European Patent Office (EPO) Series: From Alicante to Munich: Another Smooth Ride
Campinos is intent on transforming what was originally envisaged as a temporary public office into his own permanent personal feather-bed
Daniel Pocock and the Important Observation About Threats of Cult-Like Behaviours (No Rationality, No Reason, Just "Mob Rule")
It's a threat to Europe's sovereignty
The "PIP Parade" of IBM's Lousy Management, Which Said "Blockchain" Was the Future
In a healthy company such a CEO would be punished for utterly wrong visions and predictions. Not at IBM...
SLAPP Censorship - Part 135 Out of 200: Limited Liability Partnership (LLP) That Does Not Disclose Financial Activities Before August
It certainly looks like they keep losing the remaining women that still exist in the firm
Links 31/07/2026: "Climate Cover-Up Continues" and Pesticides "Cook the Planet"
Links for the day
Datacentre 'Boom' Sceptics Aren't Luddites, They Recognise a Threat to Human Survival (Not Limited to Climate Change)
Archaeologists very well know that no species will survive forever
Microsoft's Claims Are Based on a Big Lie
the bubble is coming to its hard limits
Don't Lose Sight of the Impact of "End of 10" (Vista 10)
GNU/Linux has taken off fast
Microsoft's Debt Continues to Steadily Increase, Not Counting Hundreds of Billions in Secret/Hidden Debt
The mass layoffs will carry on, maybe labelled LITE
IBM is Circling Down the Drain, the 'Growth' Comes From Beancounting Tricks and Salary Cuts
IBM was down 2.17% yesterday
Microsoft's "Headcount" Distracts From How Big a Cull It Had This Month
It also speaks of numbers "[a]s of June 30" though the "buyouts" were effective July 1 and since then well over 10,000 workers have vanished
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 30, 2026
IRC logs for Thursday, July 30, 2026
Gemini Links 31/07/2026: Music, Journaling, and Longing
Links for the day
More Fake News From (and for) IBM, Nobody Ever Held Accountable for Fraud
Companies that turn a blind eye to their own corruption end up recruiting more corrupt people and sacking those who object to the corruption
Links 30/07/2026: Smol Document Server and More PalmOS-ing
Links for the day
Links 30/07/2026: Microsoft Refuting Its Own Slop Hype and "Amazon Is Gutting Its Hey Hi (AI) Division" (GAFAM Bubble)
Links for the day
Today The Register MS Published "AI" Spam and Fake Article by "Senior Technical Marketing Engineer"
unethical practices
Cult inquiry parliament leak fallout
Reprinted with permission from Daniel Pocock
Techrights Will Always Protect Sources
Our #1 priority is sources
European Patent Office (EPO) Series: Legal Concerns and Suspicions of Irregularities
complaints submitted to OLAF
The Era of Silence
So stay silent, remain hidden
GAFAM and IBM Dying in Massive Debt, Hence the Mass Layoffs (Increasingly Silent Layoffs That the Media Fails to Mention)
the integrity of this economy is only as good as its leaders or those who govern the market
TheLayoff.com Deletes Comment That Called IBM's Previous CEO, Ginni Rometty, "Gin 'n Tonic"
It is hard to believe the comment was deleted for being a duplicate (in another thread)
The Mainstream Media Continues to Overlook or Intentionally Ignore Hundreds of Billions in Hidden/Secret Microsoft Debt
the issue is that Microsoft's crisis is a lot greater and broader than this
SLAPP Censorship - Part 134 Out of 200: What "Majority Rules" Tell Us About the Litigant
we press on with this series
Overshoot Day Sites That Contribute to the Problem
Some of these are not even accessible (at all) without JavaScript
Microsoft May Have Gotten Rid of 8% of Its Workforce This Month
It's hard to know what's really going on because there's no transparency due to NDAs
Links 30/07/2026: "Age of Irrationality", Google Losing Money, and "House of Ellison is on the Brink"
Links for the day
Gemini Links 30/07/2026: Homeworlds Notes and Manuscript Submitted
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 29, 2026
IRC logs for Wednesday, July 29, 2026