> By Anyone I didn't mean end-users.
then it isn't anyone.
>and the same can happen in the WEI case too
It is impossible to happen in this case.
If client has to be certified, then as product OS must be certified out-of-the-box for non-technical user. This will make sure 97% of market is covered by Apple, Microsoft and Google - these are "Authorities" web will have - even if the remaining few percent would be unified - it still will lead to most often then not "not being included" as trustworthy from server side.
>The TLS analogy stands.
no it does not. TLS cares about connection not OS stack. Also power dynamic flows in opposite direction.
>Ofcourse noone can trust self-certification.
If you want you can - because You (user) can import any certificate.
The problem for me is that:
[Free/Open] Source/Linux in their entirety can be attested only if self-certification is possible. AND
Self-certification means that WEI doesn't work. AND
Any proposal that excludes any OS (or Linux distribution) from web is unacceptable.
Do you see logical outcome which this reasoning leads me to?
>No browser has made the decision to trust only one authority.
But it is not the browser here who has the final power "to trust", it is the server. And companies will only care about Windows, Mac(Safari), Android and Chrome.
>A motivated and funded organisation can become an Authority (like Let's Encrypt did)
Let's Encrypt could do that because TLS works in reverse direction and it is website that must be certified not the user.
> At the "trust-me-bro" game bots are more convincing than real users.
Yes exactly which is again everyone's point - for 10001 times and again "You cannot trust the client" - it is impossible to create privacy/[freedom of use for browsers and OS]-focused 'secure' and perfect attestation about client.
One has to give - 'security'/perfection or privacy/[freedom of use for browsers and OS].
We calculated what this proposal brings and rejected it on basis that bad is bigger than potential 'good' it can bring.
And again to put it clear - you need bots: search crawlers, web archive bots, URL scanners.
So put it clear - it is clearly from my perspective a wrong proposal.
P.S.
This another thing worth considering if you think WEI will create real security:
https://news.ycombinator.com/item?id=36985317