Hacker News new | past | comments | ask | show | jobs | submit
> This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.

I think the "digital tyranny" is a side effect, not the main goal. They're "mainly a means" to prevent certain kinds of MITM attacks.

I always thought the main goal was to force people to pay money for certificates.
Let's Encrypt certificates are free.
You could that with a much saner approach like DANE.
Not back when SSL and the PKI ecosystem was developed.
loading story #48469917