Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but CAs can charge money based on (more or less) number of CA root cert installations on the target devices for a company.

Some of your competitors have had their current root certs in device preinstalled for a lot longer than you. Entrust and GlobalSign have 2048 bit roots with Not Before before 2000.

If I'm going to go with a Johnny come lately root, I may as well use LetsEncrypt because it doesn't cost money. Also, audio drivers may get you desktop share, but getting into the platform store on mobile is a lot harder.



The major trust stores partition their trust of a root by purpose. So Microsoft's trust of a particular root for signing certs that are used in driver code signing is separate from not only Apple's trust of same but also Microsoft's trust of that root for signing TLS certificates. Let's Encrypt doesn't ask for any "trust bits" besides the Web PKI, ie TLS certificates and that's completely deliberate.

Purposes other than TLS server and /maybe/ S/MIME are not subject to any meaningful public oversight, you are entirely trusting Microsoft. Which for drivers, or Xbox games is probably fine but it's worth keeping in the back of your mind.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: