On Tue, December 22, 2015 01:15, Christoph Anton Mitterer wrote:
> Control: tags -1 + wontfix
>
> On Mon, 2015-12-21 at 10:23 +0100, Thijs Kinkhorst wrote:
>> Such polarizing comments are not welcome and do not serve to improve
>> Debian. I'm closing the bug now.
> I'm afraid when factual issues are considered polarising.
> Well serving examples for such CA's should include e.g. CNNIC or
> TURKTRUST (yeah, of course, it was an "accident" that they created
> forged google.com certs and placed them in the wild o.O)

Your statement was:
"Given that Mozilla includes for money basically any
CA nowadays, even such which are inherently untrustworthy"

As you've clarified, apparently your opinion is that audits alone are not
reliable to determine worthiness of inclusion and you wish to see full
certificate subjects to better make your own choice of which CA's to
trust. I personally doubt whether the C= field is a reliable indicator of
that, but that is up to you.

By not formulating it this way, but instead choosing to use the statement
above 'will do (basically) anything for money', you choose to put focus
explicitly on the fact that it costs money and highly suggest a moral
judgment of their operation. It is really not a matter of language
difference that you choose to play the money card. It doesn't help to add
the claim that some CA's are 'inherently' untrustworthy in the same
sentence, which further reinforces the connection between accepting money
and doing something morally rejectable.

It's clear to me that you're strongly opinionated about the workings of
the CA system; your concerns also surface again in your followup. However,
I believe the BTS is not the right platform for that.

As for your request, I will reopen it and we can consider the
possibilities of it. I do hope that in the future you can show some
restraint in your approach.


Cheers,
Thijs

Reply via email to