I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. The incentive for a mass-market browser is to trust pretty much everything, but I'd prefer to use a browser that is a bit more paranoid. If a website can't load properly because I don't trust one or more of the CAs, I mi…
> I wish browser vendors would let me choose a trusted entity and make it simple for me to trust only CAs that my trusted entity supports, or the intersection of what multiple trusted entities endorse. This is an idea that I hear in variations from time to time, yet I think it's utterly wrong and goes against everything we know about IT security UI. The reason why HTTPS works at scale and is - with all its weaknesses…
Suppose 5% of CAs are compromised. Is that a success? It is if you compare it to everyone using self-signed certs, but it is not if you consider that there are likely broad vulnerabilities that can be silently exploited by some groups/nations.
We don't hear much about man in the middle attacks because we have no reason to be aware of them.
> it just works
The point of my remark is not to suggest that a list of trusted CAs compiled by someone like Bruce Schneier would result in a broken web. If it would, then it's hard to argue that the system is not already broken.
The point is to allow experts to establish authority on the basis of careful (possibly paranoid) stewardship of a list of trusted CAs. Then when an attack is revealed experts who whitelisted that CA lose a bit of credibility, and those who blacklisted it gain some.
As it stands, firms that ship a default list of trusted CAs have an incentive to err on the side of whitelisting, and then claiming "oops we had no idea that CA x was compromised..."
There are clues about the relative trustworthiness of CAs, some of which are simply the governments that have jurisdiction to demand private keys, etc.