CERT Internet

#DigiNotar and paying for an audit

The question Mozilla, Microsoft and Apple should be asking themselves now is:

Which other CA do they trust based on an audit by PwC? Their green light on DigiNotar was so flawed that I have serious doubts about anyone else they certified as a trustworthy CA.

This is a bit like the financial rating agencies at the height of the 2008 banking crisis: why the hell should I trust the audit/rating of someone who is paid by the people they are auditing/rating and who need an “all fine”/AAA result?