by janrinok on (#662MF)
fab23 writes:Last week Bruce Schneier published An Untrustworthy TLS Certificate in Browsers and now Ian Carroll has published Security concerns with the e-Tugra certificate authority.Ian is best known for the death of the EV (Extended Validation) certificates. He legally registered a colliding entity name and then got an EV certificate for his site stripe.ian.sh. As this site is not online any more, a good write up of this is Extended Validation Certificates are (Really, Really) Dead by Troy Hunt.Troy Hunt is also known for his website ';--have i been pwned?.Schneier suggests that it might be time to disable / remove trust for the following Certificate Authorities (CAs):