Hacker News new | past | comments | ask | show | jobs | submit login

WoSign was also caught red-handed backdating certificates to avoid the SHA1 deprecation.

So you can't trust that information either. As mentioned in a different thread, whitelisting certificates extracted from CT logs is the only really viable choice here.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: