@LaF0rge @sysmocom granted, I do trust the GSMA more than Beijing, but that's more due to the fact that conflicting desires if GSMA members tend to be harder to steer.
- Similarly GAFAMs conflicting ideas prevented them from enshittifying Linux.
Still, I think that end users and device integrators should have full control over the certificates and root of trust, including the ability to add alternative Root-CAs and even removing GSMA's Root-CA (similar to how "Secure Boot" should've been done instead of #CensorBoot!)
- Whether it would be a wise decision to yeet the GSMA cert is a different story, but given what I know in terms of "security" I'd certainly not trust #Bundesdruckerei and it's subsidiaries to be competent.
Certainly being able to exercise full control would make a lot of #osmocom's development easier.