
An Untrustworthy TLS Certificate in Browsers

The major browsers natively trust a whole bunch of certificate authorities, and some of them are really sketchy:

More details by Reardon.

Cory Doctorow does a great job explaining the context and the general security issues.


