Bonum Certa Men Certa

Transport Layer Security (TLS) is Fine, Centralised Certificate Authorities (CAs) Are Not

Video download link | md5sum b147528fd1ea28881ed4578632fbd8b7 War on Decentralised Internet and Computing Creative Commons Attribution-No Derivative Works 4.0



Summary: There's a lot of misconception/misunderstandings about what the Certificate Authorities (CAs) are, what they're for, how they work, and why they don't actually tackle the biggest security and privacy problems, they're mostly about centralisation of control and outsourcing of "trust" from pertinent sites/services to monopolies, empires, and oligarchs

SOME days ago someone was "[s]houting out to @tuxmachines to check your server. SSL certificate-based error messages are flying..."



This was not unforeseen. A lot of people sadly believe what Web browsers tell them, not bothering to take into account the agenda promoted by such Web browsers. It's about control and centralisation, it's not about security and/or privacy. A "malicious Web site can easily get a TLS certificate from a CA and turn the padlock on your browser green and go ahead and load," DaemonFC reminds us. "And it's still a malicious Web site."

"Let's Encrypt even admits that they do nothing to protect you from a malicious Web site, and suggest reporting those to Google and Microsoft," DaemonFC adds.

"A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia."Those who say that getting a 'good' certificate is 'free' may be missing the point. It is like buying a 'secure' boot certificate from Microsoft on the 'cheap' (until the OEMs toss them out). We wrote about this in relation to Certificate Authorities before, with focus on the "big fish", Let's Encrypt [1, 2, 3], or LE.

The video above revisits this subject. A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia. Now that the centralised systems are in place, censorship is vastly stronger. Is this security???

A given Gemini address is accessible so long as there's a certificate in place, even a self-signed one (vouching for oneself). The same model ought to have been adopted for the Web. For online banking it would help if banks sent expected fingerprints, e.g. by post. Outsourcing to monopolies isn't the way to go.

"Outsourcing to monopolies isn't the way to go."Readers might correctly spot the resemblance or notice the similarity to UEFI 'secure' boot. First they start with recommendations, saying it is all about security and enhancing safety. And then intimidation, seeking compliance from people who disregard the recommendations. Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered. So this is a form of blackmail for lock-down, initially marketed as a well-meaning security scheme. They're insincere about motives. Nothing here is "free"...

Right now, after we've witnessed expansion in Web censorship, we believe stronger resistance will be needed by explaining to people what's happening. Remember that this is not about security; it's all about control and one day revoking certificates can be weaponised further and further, just like DNS-level censorship, denial of ClownFlare access, and so on. They typically start with "pirates", "terrorism", and "the children" before resorting to political angles. CAs can very easily and immediately be leveraged for outright censorship.

"Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered."In the video above I remind people that the Linux Foundation's LE has already revoked millions of cerificates before (without even properly explaining what had happened!) and it'll happen again sooner or later. Maybe at some point they'll just decide to revoke all LE certificates for Russian sites, citing some political "sanctions". Then what? Who's next?

As an associate noted yesterday, "those that control the signing authorities can issue revocations at any time they feel like it and for any reason they feel like..."

In the case of Debian, we recently saw how trademarks get leveraged to censor criticism and hide problems. They just confiscate critics' Web sites. Maybe we'll do a video about this soon, seeing that the debian.community site is now succeeded by debian.day and debian.news. It's a namespace battle in DNS.

DaemonFC concludes: "The only thing that HTTPS does do is help keep what you do to interact with the server private from outsiders, and that is important. But if you fall for a site claiming to be your bank because it has a green padlock, that doesn't help you avoid a scam. One of the reasons I used to promote HTTPS Everywhere to everyone was because I believed the user should have the option to try to force it on with as many sites as possible. But I never would have argued for a system where HTTP is basically deprecated without TLS and browsers try to say there's something wrong with accessing such a Web site if you don't mind your information between your browser and that site remaining private. It's a good "upgrade". It is. It stops things like the Man-In-The-Middle Attacks that Comcast was using in order to spam its customers and inject advertisements into Web pages. So that's why I started using it. I thought it was outrageous that wherever I went, here's Comcast injecting alerts about data usage or ads for their TV package into my Google searches. HTTPS breaking that is a happy side-effect of what it does."

"I was big on the idea of bringing CACert into the certificates package used by Mozilla, but they always found some bullshit reason not to. Like, they didn't even want to talk about it. The whole situation with certificates is a legacy of Netscape. All of the old "players" that are really valuable and "trusted" by just about everything started out that way because Netscape Corporation put them in the Netscape Navigator browser. Then Microsoft came along with their stolen Internet Explorer product (they stiffed Spyglass Mosaic and then didn't pay them) and lobbed all the same certificates in so that sites working in Netscape Navigator would also load in Internet Explorer. And then the tragedy just kept expanding from there. Opera had to throw all the same certificates in because they've never had more than 2% of the browser market. The user has really no control over how this works. It's always been 100% Big Business. From Netscape to Microsoft to Apple and Google."

"Remember when they had that Diginotar CA that was compromised? An entire CA! They had to revoke and remove an entire CA. What a mess that was. Everything in that "chain of trust" was broken and all the sites that used it had to get new certificates, and many Windows and Mac developers got caught with their pants down and had security alerts warning the users not to install the software that the OS was saying "THIS IS FINE!" about yesterday. That was hilarious, and sad. Sad because everyone watched what ensued and nothing was fixed. They revoked one CA and caused all sorts of Hell, but it could happen with any of them."

They still push this very same agenda for software, not only Web sites, various services (including IRC), and booting.

MinceR then said that "PKI as a whole is badly designed."

Recent Techrights' Posts

The Legacy of Gerstner (Rapid Destruction) Continues at IBM
They say IBM never recovered from Gerstner, who instead of saving the companies (IBM and others he claims credit for) set up a collision course of rapid shrinkage
'Cancel Culture' Isn't About Empathy, It's About Making Good People Homeless
Seeing what they did to RMS, remember that those "concern trolls" are about everything other than ethics and morals
Daniel Pocock in The Nerve
Lots of publicity owning to the enrollment
SLAPP Censorship - Part 148 Out of 200: The Manosphere
Those people don't just threaten our national sovereignty, press, democracy etc. They also endanger women everywhere.
GNU/Linux Reaches 10% "Market Share" in statCounter
As of this morning
Voluntary' Layoffs and 'Proper' Layoffs at IBM This Year
When will IBM management confess that 15% of staff is already marked for potential removal?
 
'Voluntary' Layoffs (a Form of Silent Layoffs): Microsoft Global Voluntary Separation Agreement (GVSA) in August 2026 and September 2026
Today and yesterday
Microsoft Sees Windows on Fire, Pours Gasoline Over It
The latest move from Microsoft defies logic
Racing Towards "Woman Zero"
They don't seem to value women
Counters in Clacton Commence in 3 Hours at Clacton Leisure Centre
Even a few hundreds of votes for Pocock would be considered a great success
Swiss army to attack 2,900 domain name owners? Cult of ETH Zurich & Debian
Reprinted with permission from Daniel Pocock
IBM's Bluewashing of Confluent Carries on, More Layoffs Coming, Same Likely Applicable to Red Hat
September 30 is a day before this next phase of bluewashing at Red Hat
Headlines About Microsoft and Ransomware, But They're "SPONSORED FEATURES" at The Register MS
The Register MS habitually publishes LLM slop too
Links 13/08/2026: K-pop Suicide Due to Social Control Media, Legal Problems for Facebook Over Safety
Links for the day
Why Support Daniel Pocock
Our readers who come from IBM and the EPO are certainly familiar with the tactics of censorship and what that sort of censorship leads to
Gemini Links 13/08/2026: Health, Partial Eclipse Sketches, and Guilelessness
Links for the day
15% of IBM Marked for Potential Termination, PIPs are the "New Layoffs" (or RAs) at IBM
IBM is a dying company, but it does not want the press to say this or for people to understand that
Links 13/08/2026: "The Rise of the Measles-Industrial Complex" and Spotify Curbs Slop
Links for the day
Daniel Pocock on Australia's 9News (Nine Entertainment)
This gives visibility to software and technology issues
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 12, 2026
IRC logs for Wednesday, August 12, 2026
Gemini Links 12/08/2026: Losing a Child, "The OpenWeb Needs Diversity", and Gmail Woes
Links for the day
Links 12/08/2026: Trouble in Proprietary Chaffbot Company 'Open' 'AI' and Slop "Investors Are Suddenly Quaking in Their Boots"
Links for the day
Daniel Pocock in National News in Australia the Day of the Election
"Posted 20m ago" (Thursday in Australia), it's timed nicely to help illuminate Pocock and give him last-minute exposure
The Register MS Has Just Published Slop Spam for NVIDIA and HP, It Says "AI" 43 Times
As usual, The Register MS ought to be ashamed of itself for participating in it
The Slop Debt (Trillions of Dollars, Money That Does Not Exist) is Causing the Collapse of GAFAM et al
This slop hype will end up like "metaverse", except "metaverse" never ended up justifying trillions of dollars in "investment"
Simpler Means More Reliable
The simple old way of local storage and local backups is still the best
Clownflare and statCounter See GNU/Linux at ~8% in Norway
Norway has long championed GNU/Linux compared to the rest of Europe
Social Control Media is the Opposite of Information
That says a lot about social control media
Clacton manifesto: Reform UK hacking, leaks, raw sewage & 8GB Swiss Archive
Reprinted with permission from Daniel Pocock
statCounter Today: ChromeOS + GNU/Linux Measured at 10.98% Globally (Desktops and Laptops)
Clownflare does not quite refute this
The Register MS Has Just Published Fake Article About Replacing Linux With Proprietary Google System, "Sponsored by ASUS."
All of those things are proprietary GAFAMware
Links 12/08/2026: "X’s Advertising Business Continues to Tank", "Stop Feeding the Billionaires"
Links for the day
Lack of Empathy Rampant in the Sector
Sociopaths are sociopaths. They cannot help themselves
Before the "Big Tech" (That Almost Everybody is Forced to Use) Was Controlled by Men Who Hate Women
Such rejection and even hatred of women qualifies/enshrines oneself as an "incel"- a dangerous and violent online cult
In Defence of Hoarding CDs, More So When Digital Restrictions (DRM) Come to More 'Content' and Even Offline/Physical Media Won't Work When Some Remote Server Says "No" (or Goes Offline)
made to serve and entertain owners, not to allow companies like Sony and Microsoft subjugate owners
Clownflare: In Finland, Birthplace of Linux Kernel, GNU/Linux Now Bigger Than Apple's MacOS
It's not just in Finland where we see such trends
More Mass Layoffs Due to Monumental Debt Excused as "Investment" (in Slop)
They're maxing up the private debt and their country is already insolvent
METRO Interviews Daniel Pocock a Day Before Election
The article is behind a wall that blocks people who block ads
Enshittification More Than a Century Ago
Is enshittification more than a century old?
GNU in 1991 (35 Years Ago): Compiler and Lots More Ready, Linux Now Becoming 'Vibe Heap' (Slop Replaces Real Code)
Without curbs in place, many Linux developers will flee
Company-Wide 'Reorg' ('Redundancies') at IBM, Mark October 1st 2026 in the Calendar
Is Oct 1 the new Apr 1?
SLAPP Censorship - Part 147 Out of 200: The SLAPP Series is 'Slow' Because Timing Matters
It is important to stress that after this series is finished there will be many more series, with some of them showing raw evidence of what we've been illuminating and telling
Even ZDNet Accepts That "Market Share" of GNU/Linux May Have Doubled on Desktops and Laptops
GNU/Linux is definitely growing, and quite quickly in fact
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 11, 2026
IRC logs for Tuesday, August 11, 2026
Microsoft Layoffs and Shutdowns Continue This August, Morale Low, Employees Set Up Giant Inflatable Rat to Protest Against CEO
nothing demonstrates their anger better than what they did to the CEO
Gemini Links 12/08/2026: Sophomore Slump, Mandatory Phone Addiction, and Vintage Web Game Gallery
Links for the day
Summer Layoffs and 'Redundancies' (Cost-Cutting) at Microsoft and IBM
IBM is merely buying its revenue - an unsustainable strategy that aims to hide the company's rapid decline
Links 11/08/2026: Tensions South of China and Stingy "YouTube Doubles the Eligibility Requirements" (to Get Paid)
Links for the day
The Independent (UK) Today: "Independent candidate Daniel Pocock is concerned about media issues."
Let's see what results say around Friday
Gemini Links 11/08/2026: Stargate, Stargazer, Air-gapped Environments, and SystemVerilog Simulator
Links for the day
The Slop ('Linux') Foundation Celebrates 35 'Linux' Years a Week After GNU/Linux Turns 43
they'll keep on trying to change history
Keumars Afifi-Sabet Produces Useful, Informative Coverage Regarding Privacy
And it's good for Richard Stallman
Confirmed: Microsoft Layoffs in August 2026, Entire Operations Shut Down Too
Microsoft is just bleeding
Paying With Cash in 2026
Cash isn't going away. Not any time soon.
Blocking Tor Is Not a Solution, It's Paranoia
Tor is not a crime
Oligarchs and Their Footsoldiers Are Most Enthusiastically Loud About the Things They're Attacking
Like "Microsoft loves Linux"
FOSSY (SFC) Platforming GAFAM, Sells Endorsement
Houston, we have a problem here
Not Allowing Misogyny and Misogynists to Run the World
We stand with (and for) equality, justice, and freedom
"SPONSORED EXPLAINER" at The Register MS is Just More SPAM "Sponsored by HPE."
This is a great example of crap 'journalism'
IBM Won't Hire (or Hardly Hire) This Year
IBM is bluffing with buzzwords while shrinking out of existence and reducing salaries
SLAPP Censorship - Part 146 Out of 200: An Industry of Plagiarism, 'Normalised'
they pursue personal enrichment by stealing from Free software developers
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 10, 2026
IRC logs for Monday, August 10, 2026
5.1k Capsules Known to Lupa, Gemini Protocol Crawler
If no limits (e.g. 10k max per capsule) were imposed on crawling, there would likely be millions of pages in the database
Gemini Links 11/08/2026: Waking Up Earlier, Whining About LLMs as Destructive Plagiarism
Links for the day
Links 11/08/2026: "The Enemy Is the Platform" and 'Vibe' 'Coding' Shown to be Little But Plagiarism
Links for the day