Hacker News new | past | comments | ask | show | jobs | submit
Yeah but isn't the point of these certificates to express trust?

The point isn't (or: shouldn't be) to forcefully find your way through some back alley to make it look legit. It's to certify that the software is legit.

Trust goes both ways: we ought to trust Microsoft to act as a responsible CA. Obfuscating why they revoked trust (as is apparently the case) and leaving the phone ringing is hurting trust in MS as a CA and as an organization.

who on planet earth trusts a piece of software because Microsoft signed it?
loading story #47688461
loading story #47689393
loading story #47688239