Root CA Trust

Discussions focus on how browsers and OSes handle trust in root certificate authorities, including manual installation of custom CAs for corporate traffic monitoring, MITM attacks, and challenges with trust stores and certificate pinning.

πŸ“‰ Falling 0.4x Security
5,625
Comments
20
Years Active
5
Top Authors
#1657
Topic ID

Activity Over Time

2007
3
2008
18
2009
28
2010
82
2011
151
2012
149
2013
286
2014
355
2015
551
2016
478
2017
425
2018
345
2019
425
2020
472
2021
303
2022
378
2023
495
2024
324
2025
340
2026
17

Keywords

US CNN MITM mozilla.org CNNIC MIME TLS ROOT CA OS root cert certs certificate ca trust cas signed browser certificates

Sample Comments

vbezhenar β€’ Jul 18, 2019 β€’ View on HN

Browsers always trust manually installed CA roots, because that scenario is used by many corporations to monitor their traffic. OCSP, HPKP, etc won't help.

icebraining β€’ Feb 28, 2017 β€’ View on HN

If the savvy want this they can already have it, it's just a matter of removing the certs from the browser's CA store.

yaris β€’ Nov 2, 2023 β€’ View on HN

IIRC one cannot tell the browser to not trust root CAs, that's why all the fuss.

evv β€’ Jan 15, 2014 β€’ View on HN

Really, how?? Wouldn't that require the installation of a custom root certificate on every client?

LeoPanthera β€’ Sep 23, 2014 β€’ View on HN

I might be interested - is your root cert in all common browsers/OSs?

someguydave β€’ Jun 5, 2024 β€’ View on HN

it depends on your use case, but yes you would probably need to load at least your browser with your own CA. It’s a good hygiene to manage your own keys though

ilyt β€’ Feb 6, 2023 β€’ View on HN

Application doesn't even need to use root CAs from system, it can ship its own; the problem starts when you try to make system browser part of your app

tomjen3 β€’ Feb 24, 2015 β€’ View on HN

Can't we just remove their root certificate from the trust stores then?

gruez β€’ Oct 19, 2020 β€’ View on HN

As opposed to what? Using the OS's trust store? Getting the user to manually trust CAs?

snek β€’ Feb 26, 2019 β€’ View on HN

Why can't they just install their own self signed root ca on all their computers and continue MITM it?