Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can actually opt out of that mechanism: you can use your own, untrusted CA. The point of CT is to improve trust, and I seriously have doubts trusting the 300 independant (?) CAs my browser "trusts" [0].

Sure, having an infinite, append-only log of domain names for which an HTTPS certificate ever was issued sounds like a GDPR issue. But if it also helps catch bad actors before they can even set up their phishing pages, I'm all for it.

[0] https://hg.mozilla.org/releases/mozilla-beta/raw-file/tip/se...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: