Sectigo’s Wrongful Revocation of RustDesk’s EV Certificate: A Concerning Precedent for the Software Security Ecosystem
DigitalDilemma @ digdilem @lemmy.ml 帖子 3评论 697加入于 2 yr. ago
DigitalDilemma @ digdilem @lemmy.ml
帖子
3
评论
697
加入于
2 yr. ago
CAs exist on trust and trust alone.
This, along with any other mistake, erodes that trust and will have damaged Sectigo's reputation at least as much as Rustdesk's.
I doubt there's any conspiracy or higher figure at work here. Just human error.
Rustdesk will probably have a claim for financial losses and good luck if they pursue that - the admission of a mistake and breach of protocol makes it seem likely to be settled very quickly. The tone of this report suggests that this is somewhere they'll be heading towards and I suspect Sectigo will pay handsomely to make this story short lived.