Earlier quoted context omitted.
> Not all European CAs meet browsers' root programs requirements. That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.
I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…
Is that really a question to be taken seriously? One is a private organization, completely unaccounted for and in a foreign jurisdiction, who sets their own rules and follows up on themselves.
The other is accountable and audited by independent auditors in a system which upholds separation of power and keeps independent media?
(Just to clarify: Neither Mozilla or anyone else should accept QWAC or any other standard in the face of legitimate concerns, of course. That's not what trust means.)