Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

These kinds of attacks are usually run by a major threat actor (i.e. nation state), targeted, and not run at large scale. Certificate transparency is unlikely to help in this case. Key pinning was the more secure option. For some issues see:

https://www.agwa.name/blog/post/how_will_certificate_transpa...

https://tools.ietf.org/html/draft-ietf-trans-threat-analysis...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: