Add Honest Achmed's root certificate (2011)
bugzilla.mozilla.org
Add Honest Achmed's root certificate (2011)
1–10 of 29 posts
Re: Add Honest Achmed's root certificate (2011)
#2Only 11 years later, Elon Musk started selling blue check marks on Twitter. Achmed was ahead of his time.
Re: Add Honest Achmed's root certificate (2011)
#3Classic of the genre.
I remember around the time of the diginotar horrors looking at DANE and DNSSEC. As I understand it, DANE still isn't supported by browsers, and DNSSEC is still in a pitiful state.
Re: Add Honest Achmed's root certificate (2011)
#4Only 11 years later, Elon Musk started selling blue check marks on Twitter. Achmed was ahead of his time.
They were already meaningless
Re: Add Honest Achmed's root certificate (2011)
#5I never find this kind of stuff funny... it's more snark than humor. It's also got a weird racial tinge on the tiresome trope of a somewhat distrustful middle eastern laborer, which makes it gross.
Re: Add Honest Achmed's root certificate (2011)
#6How much does an audit cost? How much work would it be to get Honest Achmeds root cert added to all major OSs and browsers?
Re: Add Honest Achmed's root certificate (2011)
#7Inclusion policy is here
12 years ago, that meant something different.
Re: Add Honest Achmed's root certificate (2011)
#8[dead]
Re: Add Honest Achmed's root certificate (2011)
#9Contemporary discussion, nearly twelve years ago:
Re: Add Honest Achmed's root certificate (2011)
#10For a long time, I've argued we need leaf certificates to be double signable. That way there can be two chains of trust for a website. Then dropping a CA doesn't matter much, since all serious parties should have multiply signed paths to various roots of trust. Hence we solve the problem of CAs becoming to big to fail.
The current way cross-signing works is almost an accident, and only works for intermediate certificates. Because the 'signing cert' is looked up by name. An intermediate cert can be published twice with the same name, same key, but different signatures and signing cert. Hence doing this for a leaf certificate would mean 'just get two certificates'.