_Recent breaches at CAs have exposed several systemic vulnerabilities and market failures inherent
in the current HTTPS authentication model: the security of the entire ecosystem suffers if any of
the hundreds of CAs is compromised (weakest link); browsers are unable to revoke trust in major
CAs (“too big to fail”); CAs manage to conceal security incidents (information asymmetry); and
ultimately customers and end users bear the liability and damages of security incidents (negative
externalities)._ — from the conclusion; only 30 pages