Bonum Certa Men Certa

Transport Layer Security (TLS) is Fine, Centralised Certificate Authorities (CAs) Are Not

Video download link | md5sum b147528fd1ea28881ed4578632fbd8b7 War on Decentralised Internet and Computing Creative Commons Attribution-No Derivative Works 4.0



Summary: There's a lot of misconception/misunderstandings about what the Certificate Authorities (CAs) are, what they're for, how they work, and why they don't actually tackle the biggest security and privacy problems, they're mostly about centralisation of control and outsourcing of "trust" from pertinent sites/services to monopolies, empires, and oligarchs

SOME days ago someone was "[s]houting out to @tuxmachines to check your server. SSL certificate-based error messages are flying..."



This was not unforeseen. A lot of people sadly believe what Web browsers tell them, not bothering to take into account the agenda promoted by such Web browsers. It's about control and centralisation, it's not about security and/or privacy. A "malicious Web site can easily get a TLS certificate from a CA and turn the padlock on your browser green and go ahead and load," DaemonFC reminds us. "And it's still a malicious Web site."

"Let's Encrypt even admits that they do nothing to protect you from a malicious Web site, and suggest reporting those to Google and Microsoft," DaemonFC adds.

"A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia."Those who say that getting a 'good' certificate is 'free' may be missing the point. It is like buying a 'secure' boot certificate from Microsoft on the 'cheap' (until the OEMs toss them out). We wrote about this in relation to Certificate Authorities before, with focus on the "big fish", Let's Encrypt [1, 2, 3], or LE.

The video above revisits this subject. A lot has happened since then, notably Russia's invasion of Ukraine, which resulted in a lot of censorship inside Russia, by Russia, and against Russia. Now that the centralised systems are in place, censorship is vastly stronger. Is this security???

A given Gemini address is accessible so long as there's a certificate in place, even a self-signed one (vouching for oneself). The same model ought to have been adopted for the Web. For online banking it would help if banks sent expected fingerprints, e.g. by post. Outsourcing to monopolies isn't the way to go.

"Outsourcing to monopolies isn't the way to go."Readers might correctly spot the resemblance or notice the similarity to UEFI 'secure' boot. First they start with recommendations, saying it is all about security and enhancing safety. And then intimidation, seeking compliance from people who disregard the recommendations. Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered. So this is a form of blackmail for lock-down, initially marketed as a well-meaning security scheme. They're insincere about motives. Nothing here is "free"...

Right now, after we've witnessed expansion in Web censorship, we believe stronger resistance will be needed by explaining to people what's happening. Remember that this is not about security; it's all about control and one day revoking certificates can be weaponised further and further, just like DNS-level censorship, denial of ClownFlare access, and so on. They typically start with "pirates", "terrorism", and "the children" before resorting to political angles. CAs can very easily and immediately be leveraged for outright censorship.

"Finally, they resort to outright locking out (blocking) anything that is not submissive, e.g. after 90% or more have already surrendered."In the video above I remind people that the Linux Foundation's LE has already revoked millions of cerificates before (without even properly explaining what had happened!) and it'll happen again sooner or later. Maybe at some point they'll just decide to revoke all LE certificates for Russian sites, citing some political "sanctions". Then what? Who's next?

As an associate noted yesterday, "those that control the signing authorities can issue revocations at any time they feel like it and for any reason they feel like..."

In the case of Debian, we recently saw how trademarks get leveraged to censor criticism and hide problems. They just confiscate critics' Web sites. Maybe we'll do a video about this soon, seeing that the debian.community site is now succeeded by debian.day and debian.news. It's a namespace battle in DNS.

DaemonFC concludes: "The only thing that HTTPS does do is help keep what you do to interact with the server private from outsiders, and that is important. But if you fall for a site claiming to be your bank because it has a green padlock, that doesn't help you avoid a scam. One of the reasons I used to promote HTTPS Everywhere to everyone was because I believed the user should have the option to try to force it on with as many sites as possible. But I never would have argued for a system where HTTP is basically deprecated without TLS and browsers try to say there's something wrong with accessing such a Web site if you don't mind your information between your browser and that site remaining private. It's a good "upgrade". It is. It stops things like the Man-In-The-Middle Attacks that Comcast was using in order to spam its customers and inject advertisements into Web pages. So that's why I started using it. I thought it was outrageous that wherever I went, here's Comcast injecting alerts about data usage or ads for their TV package into my Google searches. HTTPS breaking that is a happy side-effect of what it does."

"I was big on the idea of bringing CACert into the certificates package used by Mozilla, but they always found some bullshit reason not to. Like, they didn't even want to talk about it. The whole situation with certificates is a legacy of Netscape. All of the old "players" that are really valuable and "trusted" by just about everything started out that way because Netscape Corporation put them in the Netscape Navigator browser. Then Microsoft came along with their stolen Internet Explorer product (they stiffed Spyglass Mosaic and then didn't pay them) and lobbed all the same certificates in so that sites working in Netscape Navigator would also load in Internet Explorer. And then the tragedy just kept expanding from there. Opera had to throw all the same certificates in because they've never had more than 2% of the browser market. The user has really no control over how this works. It's always been 100% Big Business. From Netscape to Microsoft to Apple and Google."

"Remember when they had that Diginotar CA that was compromised? An entire CA! They had to revoke and remove an entire CA. What a mess that was. Everything in that "chain of trust" was broken and all the sites that used it had to get new certificates, and many Windows and Mac developers got caught with their pants down and had security alerts warning the users not to install the software that the OS was saying "THIS IS FINE!" about yesterday. That was hilarious, and sad. Sad because everyone watched what ensued and nothing was fixed. They revoked one CA and caused all sorts of Hell, but it could happen with any of them."

They still push this very same agenda for software, not only Web sites, various services (including IRC), and booting.

MinceR then said that "PKI as a whole is badly designed." ⬆

Recent Techrights' Posts

Dejan Panovski Outs linuxize.com as a Slopfarm, Another Site That Sold Out and Became LLM Garbage
From what we can gather, both images and text are slop
A Microsoft Lunduke OS (LCOS) is Not Even in Top 100 in DistroWatch, Microsoft Lunduke Just Games the Numbers Like Linspire Did (and Got 'Banned' for It)
Linspire used to send people to 'its' DistroWatch page to make the illusion of popularity
 
Gemini Links 27/09/2026: Writing Well, Productivity, and a Relaunch in Geminispace
Links for the day
Making This Site More Useful to More People
Search engines (as a concept) are under attack
Exposing Crimes of Americans (From the UK)
We must ensure UK prisons are never misused to punish/silence people who expose crimes in America
Spam and Chatbot Spam in Internet Relay Chat (IRC)
Maintaining one's own IRC network requires some housekeeping, but it's simpler than outsourcing to malicious companies
Search Engine of Techrights Improved for Better Signal-to-Noise Ratio
Our growing community needs more search facilities
Microsoft: We Love Layoffs, We Do Silent Layoffs, More Microsoft Projects/Teams/Studios Confirmed to be Shutting Down
XBox is dying. Piece by piece.
Brigading Against Women - Part VI - On Garrett and Lozza, Defamation, Attempts to Crack My Wife's Accounts, Social Engineering to Try to Take Sites Offline, Subscribing Us to Mountains of SPAM
tried swatting us
Links 27/09/2026: "Provost of Dartmouth Busted Using Hey Hi (AI) Slop for His Own Writing in Newspapers and Academic Journals" and "UK Government Enforcement Reform"
Links for the day
People and Sites Wish a Happy 43th Birthday to GNU (Today)
We've collected some examples
Links 27/09/2026: Microsoft Fired People a Day After Promotion, "Fragility of Online Journalism"
Links for the day
Brigading Against Women - Part V - SWATTING, Extortion Against Webhosts, and Lawfare Under Sworn Oath (Perjury Also)
Matthew Garrett has no qualm about still collaborating with Lozza
20 Years Later
There's a strong anti-democracy movement brewing in many places
Gemini Links 27/09/2026: Telescopes/Gskyer, Writing for Writing's Sake, and Writing Tools
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 26, 2026
IRC logs for Saturday, September 26, 2026
Gemini Links 26/09/2026: Computer Cases Dreary, Web Drowning in Botspam
Links for the day
Reform UK auditor: Electoral Commission accounts, Companies House accounts, a going concern or not?
Reprinted with permission from Daniel Pocock
European Patent Office (EPO) Series: Temporary Public Office or Permanent Personal Feather-Bed?
there are no visible signs that the Administrative Council has the slightest interest in contemplating a change in leadership at the EPO
Brigading Against Women - Part IV - Death Threats, Threats to Women, and Threats for Pointing Out, Correctly and Based on Hard Evidence, That Garrett and Lozza Talk to Each Other About Me Every Year (for 4 Years)
Brett Wilson LLP too is a toxic manosphere
More GAFAM Layoffs at Apple, Second Time in Weeks (Silent Layoffs Silently Target Older and "More Expensive" Staff)
How many layoffs happen at Apple silently and go unreported or very scarcely reported?
Gemini Links 26/09/2026: Rant About Slop Ruining Crafts (Drowning the Signal With Plagiarism) and "Going Mechanical"
Links for the day
Links 26/09/2026: Microsoft Says Notification Data Breach/Surveillance Hole There by Design, EU Rapidly Dumping Microsoft for Digital Sovereignty
Links for the day
The Former Linux News Site ostechnix.com is LLM Slop
Please do not link to sites that promote and/or spread slop
Links 26/09/2026: Volkswagen Recalling ~50,000 Cars, US Attacks Its Own Media
Links for the day
Making Oneself Obsolete With Slop
Dr. Lemire also puts on display a degree of hypocrisy
Brigading Against Women - Part III - Racism Looms Large, Not Just Sexism
threats from a racist
Microsoft CEO Calls Layoffs "Streamlining" and Says Microsoft Layoffs Are "Great to See"
The lack of honesty here is only to be expected from Microsoft
Media silence deafening as Reform UK on brink of administration
Reprinted with permission from Daniel Pocock
Gemini Links 26/09/2026: Travel, Group Insurance Death Spiral, Stargazing, and Lagrange Meets LLM Slop
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 25, 2026
IRC logs for Friday, September 25, 2026
Longtime Symbol of Microsoft's XBox Franchise, Halo, Down to Barely 20 People
The purge is huge, far bigger than submissive media cares to point out
EPO Meeting Ran Out of Time to Discuss the Scabs ('Young Professionals')
EPO staff representatives in The Hague meet a member of the 'cocaine cabinet'
The Register MS Promotes Slop for Banned Companies That Put Chinese Back Doors in Things, "AI" Mentioned 37 Times in One Page!
taking money from the undemocratic state and its surveillance outfits
Microsoft Attacked European Courts and Jurists, Now Europe Dumps Microsoft
This is because GNU/Linux is technically better, but the political factors contribute to that as well
Julian Assange Ready to Talk More (After More Than a Decade of Arbitrary, Unjust Confinement)
Two years ago, upon his release, his wife said he'd need some time off before properly or fully returning to the public eye
IEEE Tribute to Richard Stallman, Michael Tiemann, Linus Torvalds, Larry Augustin, Eric S. Raymond, Bruce Perens, Frank Hecker and Brian Behlendorf (Revolution OS Showing)
Live shortly
Winding Up Racists
What happens next shall be interesting
Links 25/09/2026: Selling Rogue, Defective Bots as "Agents" Results in PR Fiasco and Breaches; Russian 'Hybrid Attack' and "How Russia Evades Sanctions"
Links for the day
Gemini Links 25/09/2026: Arvelie Calendar, 44net, Pebbles, and Building the Bagel Concert Finder
Links for the day
Large Wave of IBM PIPs, the RAs Wave Comes After 'Low-Hanging' Fruit (Families) Disposed of
PIPs are the new RAs
Links 25/09/2026: Carcinogen Atrazine Pollutes Americans' Bodies, "Donald the Deadbeat Does Diesel", and Anger Over Data Centres Grows
Links for the day
Theory That Microsoft Cheapens Its Workforce to Push Workers Out on Their Own (Theory Advanced by Insider)
people work longer hours for less, i.e. their hourly salary is decreasing
Daniel Pocock Makes It Into Mainstream Media Again (Going After Racists)
American bigots funding blatant and shameless racists here in the UK
Tackling Racism in the United Kingdom (Racism Funded by Americans) Using the Courts
We'll talk about racism my wife and I experienced in the events leading up to litigation
Another Woman (or Women) Has Just Run Away From Brett Wilson LLP (After Barely a Month!), the Hired Guns of Garrett and Graveley (Microsoft)
They call this phenomenon "death spiral"
SLAPP Censorship - Part 200 Out of 200: Will GNU Boot Undo the Technical Damage Caused by Microsoft and Garrett? (And Garrett's Litigation Allies From Microsoft)
Today we publish the final part of this series
US Government Sites Can Now Totally Ignore Mozilla Firefox Users or Users of Firefox Derivatives
Firefox, now at 1.1% in the US (based on American government sites), has sunken to the point of no return
Things Not to Measure in Quantity Alone
More patents do not beget greater innovation
Even Microsoft Boosters Start to Doubt XBox Will Exist (It's Being Phased Out, Just Not "Officially")
This is how to phase out a business unit without officially saying so (as it might alarm investors)
Omarchy is Built on the Idea That Slop is Desirable (It's Not)
They call bots and plagiarism "agents" and "training"
IBM is Shrinking Very Fast (Silent, Unannounced Layoffs)
IBM and Microsoft both avoid WARN notices by compelling staff to leave or silently removing them with some NDA
In Some Parts of Microsoft 50% of All Staff Subjected to Layoffs, Media Pretends Only 0.1% of Staff Are Removed
This really says a lot about the state of today's so-called 'media'
SLAPP Censorship - Part 199 Out of 200: An American Burden on the British Legal System
A year ago (October 2025) the head of media (Jointly in Charge of the Media and Communications List), the judge in the Garrett case, said that this case was a waste of the court's money
EPO Management Wants Everything to be Done in Microsoft Spyware
In reality, this management should be ousted for normalising cocaine at the Office
Criminalising Opposition to Fraud
slop causes social issues
The Register MS Does Not Properly Flag Its SPAM About Slop
Signs of desperation
Gemini Links 25/09/2026: Ljubljana, Tanana River, and Curse of Slack
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 24, 2026
IRC logs for Thursday, September 24, 2026
Supporters of winding-up process staking claims against Reform UK Party (CR-2026-007405)
Reprinted with permission from Daniel Pocock
Winding-up petition leaked before service on Reform UK Party Limited / Nigel Farage
Reprinted with permission from Daniel Pocock