Rant mode: I hate utter morons who work in IT

We have secure DNS now which in theory allows the browsers to completely bypass the CAs (by simply storing keys in the DNS records). Why don't Mozilla and Google get together, introduce a source authentication based on secure DNS, run that for a while and then deprecate the whole bloody corrupt designed by the NSA CA system?
 
Absolutely true. However, I found the rant against not properly configuring a certificate in the same post as talking about a wildcard certificate had some comic value.

The mention of a wildcard cert was to demonstrate how cheap a certificate is, not as a meaningful indicator of what they should do.

And since the wildcard cert is A: stored in a quite secure location, B: is accessible by a total of two people in the enterprise, and C: isn't linked to our PKI environment, I really am not worried about it.
 
Back
Top