Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are currently no publicly trusted CAs participating in such a scheme. If there were, it'd be trivially detectable due to the millions of fraudulent certificates showing up in Certificate Transparency logs.


Of course they won't tell you that they are doing it...


They _have_ to tell you, there's no alternative option. If they don't publish the certs in multiple logs, then they aren't considered valid by browsers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: