Bonum Certa Men Certa

Transport Layer Security (TLS) is Fine, Centralised Certificate Authorities (CAs) Are Not

Video download link | md5sum b147528fd1ea28881ed4578632fbd8b7 War on Decentralised Internet and Computing Creative Commons Attribution-No Derivative Works 4.0



Summary: There's a lot of misconception/misunderstandings about what the Certificate Authorities (CAs) are, what they're for, how they work, and why they don't actually tackle the biggest security and privacy problems, they're mostly about centralisation of control and outsourcing of "trust" from pertinent sites/services to monopolies, empires, and oligarchs

SOME days ago someone was "[s]houting out to @tuxmachines to check your server. SSL certificate-based error messages are flying..."



This was not unforeseen. A lot of people sadly believe what Web browsers tell them, not bothering to take into account the agenda promoted by such Web browsers. It's about control and centralisation, it's not about security and/or privacy. A "malicious Web site can easily get a TLS certificate from a CA and turn the padlock on your browser green and go ahead and load," DaemonFC reminds us. "And it's still a malicious Web site."

"Let's Encrypt even admits that they do nothing to protect you from a malicious Web site, and suggest reporting those to Google and Microsoft," DaemonFC adds.

"A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia."Those who say that getting a 'good' certificate is 'free' may be missing the point. It is like buying a 'secure' boot certificate from Microsoft on the 'cheap' (until the OEMs toss them out). We wrote about this in relation to Certificate Authorities before, with focus on the "big fish", Let's Encrypt [1, 2, 3], or LE.

The video above revisits this subject. A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia. Now that the centralised systems are in place, censorship is vastly stronger. Is this security???

A given Gemini address is accessible so long as there's a certificate in place, even a self-signed one (vouching for oneself). The same model ought to have been adopted for the Web. For online banking it would help if banks sent expected fingerprints, e.g. by post. Outsourcing to monopolies isn't the way to go.

"Outsourcing to monopolies isn't the way to go."Readers might correctly spot the resemblance or notice the similarity to UEFI 'secure' boot. First they start with recommendations, saying it is all about security and enhancing safety. And then intimidation, seeking compliance from people who disregard the recommendations. Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered. So this is a form of blackmail for lock-down, initially marketed as a well-meaning security scheme. They're insincere about motives. Nothing here is "free"...

Right now, after we've witnessed expansion in Web censorship, we believe stronger resistance will be needed by explaining to people what's happening. Remember that this is not about security; it's all about control and one day revoking certificates can be weaponised further and further, just like DNS-level censorship, denial of ClownFlare access, and so on. They typically start with "pirates", "terrorism", and "the children" before resorting to political angles. CAs can very easily and immediately be leveraged for outright censorship.

"Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered."In the video above I remind people that the Linux Foundation's LE has already revoked millions of cerificates before (without even properly explaining what had happened!) and it'll happen again sooner or later. Maybe at some point they'll just decide to revoke all LE certificates for Russian sites, citing some political "sanctions". Then what? Who's next?

As an associate noted yesterday, "those that control the signing authorities can issue revocations at any time they feel like it and for any reason they feel like..."

In the case of Debian, we recently saw how trademarks get leveraged to censor criticism and hide problems. They just confiscate critics' Web sites. Maybe we'll do a video about this soon, seeing that the debian.community site is now succeeded by debian.day and debian.news. It's a namespace battle in DNS.

DaemonFC concludes: "The only thing that HTTPS does do is help keep what you do to interact with the server private from outsiders, and that is important. But if you fall for a site claiming to be your bank because it has a green padlock, that doesn't help you avoid a scam. One of the reasons I used to promote HTTPS Everywhere to everyone was because I believed the user should have the option to try to force it on with as many sites as possible. But I never would have argued for a system where HTTP is basically deprecated without TLS and browsers try to say there's something wrong with accessing such a Web site if you don't mind your information between your browser and that site remaining private. It's a good "upgrade". It is. It stops things like the Man-In-The-Middle Attacks that Comcast was using in order to spam its customers and inject advertisements into Web pages. So that's why I started using it. I thought it was outrageous that wherever I went, here's Comcast injecting alerts about data usage or ads for their TV package into my Google searches. HTTPS breaking that is a happy side-effect of what it does."

"I was big on the idea of bringing CACert into the certificates package used by Mozilla, but they always found some bullshit reason not to. Like, they didn't even want to talk about it. The whole situation with certificates is a legacy of Netscape. All of the old "players" that are really valuable and "trusted" by just about everything started out that way because Netscape Corporation put them in the Netscape Navigator browser. Then Microsoft came along with their stolen Internet Explorer product (they stiffed Spyglass Mosaic and then didn't pay them) and lobbed all the same certificates in so that sites working in Netscape Navigator would also load in Internet Explorer. And then the tragedy just kept expanding from there. Opera had to throw all the same certificates in because they've never had more than 2% of the browser market. The user has really no control over how this works. It's always been 100% Big Business. From Netscape to Microsoft to Apple and Google."

"Remember when they had that Diginotar CA that was compromised? An entire CA! They had to revoke and remove an entire CA. What a mess that was. Everything in that "chain of trust" was broken and all the sites that used it had to get new certificates, and many Windows and Mac developers got caught with their pants down and had security alerts warning the users not to install the software that the OS was saying "THIS IS FINE!" about yesterday. That was hilarious, and sad. Sad because everyone watched what ensued and nothing was fixed. They revoked one CA and caused all sorts of Hell, but it could happen with any of them."

They still push this very same agenda for software, not only Web sites, various services (including IRC), and booting.

MinceR then said that "PKI as a whole is badly designed."

Recent Techrights' Posts

Last Week's EPO Strike Was the Biggest (Highest Participation Rate), Hours Ago General Assembly Discussed Next (Growing) Intensity of Strikes
Well done and well attended
 
SLAPP Censorship - Part 21 Out of 200: It's About Behaviour Online, Not How Much Money From Shadowy Third Parties Gets Spent on Lawyers and Two Barristers
75+ KG of legal papers, 2 cases, 2 barristers (one hiding in the metadata) and maybe two law firms (also hiding in the metadata) against two modest people in Manchester seems disproportionate and vindicative
Links 24/03/2026: "Airports on ICE" and "Have You Paid Your “Intuit Tax”?"
Links for the day
Gemini Links 24/03/2026: Slop Interview and Why Slop Makes Lousy Code
Links for the day
Richard Stallman to Give Public Talk This Thursday at the University of Bologna (Italy)
Hardly the first time he speaks in Bologna
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 23, 2026
IRC logs for Monday, March 23, 2026
Gemini Links 23/03/2026: "Mandatory" Bad Things and Dangers of Perfection Aspirations
Links for the day
SLAPP Censorship - Part 20 Out of 200: All Roads Lead to Rome and to GAFAM Funding
Now about 10% into this series
Mass Layoffs at HashiCorp, IBM Hid Them
The media did not mention those layoffs
Microsoft Downgraded on Concerns (Lack of Growth) Amid Silent Layoffs in 2026
The press isn't functioning anymore
Links 23/03/2026: Gulf Water at Risk, Heatwave in Malaysia
Links for the day
Slop Means False, New Article by Cybershow
"We are living in a world that is rapidly divesting from reality."
Debianism election 2026 community poll created, everybody can vote
Reprinted with permission from Daniel Pocock
Links 23/03/2026: "Shocking Peter Thiel Antichrist Lectures", Robert Mueller Remembered
Links for the day
The Scandal Bigger Than IBM/Red Hat Layoffs is the de Facto "Media Blackout" About Those Layoffs
So we have a media crisis, aside from the economic crises
Gemini Links 23/03/2026: Geminispace/Elpher Enhancement and the Cerberus Cinco
Links for the day
Fear is Not a Legitimate Factor
Smart people know that trying to prevent moral people from doing the "Right Thing" will backfire
Fuel Autonomy and What It Teaches Us About Software Autonomy (or Software Freedom)
Need we wait until a "software Pearl Harbor" or protect ourselves proactively by weaning ourselves off of GAFAMware?
Scheduled Maintenance This Coming Wednesday
Other than that, all is the same and we carry on as usual
Most Press Articles About IBM Are LLM Slop, Sometimes With Slop Images
IBM basically laid off almost 1,000 people last week [...] At the moment about 75% of the 'articles' we see about IBM (in recent days) are some kind of slop
Links 23/03/2026: Security Breaches, Energy Shortages, Another SRA Scandal, and Patents on Nature
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 22, 2026
IRC logs for Sunday, March 22, 2026
Streisand Effect and Justice
This weekend this site has served over 8 million Web requests
Gemini Links 22/03/2026: "Woman of Tomorrow" and "First Steps in Geminispace"
Links for the day
SLAPP Censorship - Part 19 Out of 200: They Were Ill-prepared for Tough Questions in Cross-Examination
Very ill-prepared for the deteriorating situation caused by their clients' past behaviour towards many people, including high-profile figures who offered to testify
The Media Sold Out to Slop Bros
If you wish for the hype to stop, then stop participating in it
EPO Strike a Week From Now, After That Strikes Can Become Permanent
A week from tomorrow there will be another strike
The Only Non-IBM Staff in Fedora Council/Leadership Attacks Booting Freedom (Just Like the Master Wants)
Last week IBM laid off almost 1,000 people in Confluent and the media didn't write anything about it, so don't expect anyone in what's left of the media to comment on Fedora's demise and silent layoffs at Red Hat
Just Like a Founder of XBox Said, Microsoft XBox is Collapsing, Management Continue to Jump Ship
Nowadays Microsoft tries to promote this idea that Windows is XBox and XBox is Windows
Links 22/03/2026: Slop Triggers Emergency at Meta, Energy Prices Rise Sharply
Links for the day
Links 22/03/2026: Microsoft 'Open' 'AI' in Legal Trouble (Plagiarism, Distortion, Misrepresentation); Facebook/Meta Kills Off "Horizon Worlds"
Links for the day
Racism Dressed Up as "Choice"
Racism is rampant at IBM
Probably an All-Time Record
Our investment in our own SSG is paying off
Your Site Should Implement Its Own Search (Before It's Too Late)
GAFAM was never trustworthy
Gemini Links 22/03/2026: LLM Slop Attacks USENET, Announcing Pig (New Game in Gemini Protocol)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, March 21, 2026
IRC logs for Saturday, March 21, 2026