Search the Site

My Social
Meta
Powered by Squarespace
« Wireless Standards??? | Main | Tripods for Sale »
Tuesday
Aug142007

Do You Trust 'Kozjegyzoi Tanusitvanykiado'?

Perhaps you don't, but your computer does!

At this moment there are over a hundred Trusted Root Certifications Authorities in your browser or Operating System. Many of those don't mean anything to me.

When a Trusted Root Certification Authority is available in your browser or OS, you don't get any questions/pop-up that your entering a secured Internet connection. This means that the certificate was issued by someone trustworthy. Who decides who or what company is trustworthy?

I know most of the commercial SSL vendors like VeriSign, Thawte, Comodo, Equifax, Entrust, and Cybertrust. Those are the companies which sell most of the SSL certificates used on the Internet. But I haven't heard of Kozjegyzoi Tanusitvanykiado or IPS Seguridad. So do I want to trust certificates issued by them?

It would be nice if the browser had an extra message box (yes, another message box :-) ) to verify with the user if the CA should be trusted from this point on. This way the (pro-)user gets to decide if he wants to trust the CA (without the trouble of manually verifying the CA details on the CA website), and the basic user may rely on the recommendation from the OS/browser.

 

CA Trust Dialog

This way I can decide for myself if I want to trust some post-office in Japan or Germany.

Reader Comments (2)

That's an interesting suggestion. So I wonder how much would CAs invest in brand recognition than trying to do a good job...

January 5, 2009 | Unregistered CommenterEddy Nigg

I guess that this should depend on your business model. If a CA is working on a global scale (like VeriSign, Entrust, e.a.) trust by default, while the local CA's (limited to countries or specific usergroups) should be a user setting.

You could even combine this with regional settings in your OS. E.g. I live in the Netherlands, and we have a government CA over here (not that it's in use :) ). Since I live here, the chances are that I might even do certificate based transactions with them, so enable that CA for me.

January 5, 2009 | Unregistered CommenterWillem

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>