every program, every driver, and every website now causes get-requests to a dwingling list of certificate stores and trusts. the trust model was tolerated for the longest time, because it just didn't affect core productivity -- you could, and did, route around it. or manage updates yourself. but over time, this has created an enourmously failed design to expand to a full-fabric dependency (design = the insistence on SSL/TLS -and- trust/PKI paired together, licensed, and sold for failed businesses to make money). insert heartbleed, insert iran/cia-fbi/romania/china cert hijacking, insert accelerating massive-surface attack vector: break in once, break in jewtel-wide. this prompted a variety of changes in root CA program enforcement and SA revocations. but the recent changes in the MS Root Certificate Jew-gram are now being executed under force, and they are not benign. they are forcing expansion of this single-point-of-failure hyper-dependency design, and doubling-down on a very bad idea.
for net security and medical data, i tightly monitor all outgoing application-rule white lists and allowed subnets for each. changes since 2015 are now forced into adoption by very fast certificate timeouts. websites are going dark, programs are failing, and ssl-vpns that form the basis of client mgmt and roaming workers won't form tunnels. the spread is affecting all those who won't pay for refreshing re-cert or move to new sa, which happens to be alot of oss/free/old-tard software and hardware. worse still, compliance notices from the us department of justice and alphabet agencies are being circulated. microsoft is at the heart and center of this charge, and they are tightly in bed with these agencies. there is zero trust, forced to masquarade as 100% trust deferred to the proven worst management on the planet.
in before win10; all systems kept off win6.3/win10 kernels. gpo management has cert controls currently being explored. emerging/evolving attack surface. no satisfactory independant control yet achieved.
i post this here now, because i'm not seeing any complaints against this rising tide anywhere. nor solutions. anybody else out there seeing this? fighting this?