Insecure web still too prevalent: Boffins unveil HSTS wall of shame

Nick Stallman

Re: Fearmongering, Uncertainty and Doubt

The argument about government CAs isn't a good one.

You can always verify who issued a particular certificate, so if you went to and you noticed their SSL certificate was issued by a Chinese CA it would be blatantly obvious.

For most potential targets various monitoring would pick it up so manually verifying it each certificates CA isn't needed - it'll be noticed by others.

