| ▲ | airza an hour ago | |
The problem is that there is no out-of-band mechanism for update like other devices. If your CA certs are bad on your mobile application, you can push an out-of-band update via the device's app store. If your CA certs are bad on a website you access via your browser, the means of updating them is... the browser. You can't get new certs without using a TLS connection you didn't want to trust anyway. | ||