Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure, however this has the effect of showing any eavesdropper exactly which certificates you're trusting (and when), and thus in most cases which web sites you're visiting. It also tells the Certificate Authorities the same things about sites they've issued certificates to.

Now, I assume that the list of people who visit Porn Hub isn't valuable enough to justify the CA (DigiCert again) explicitly monitoring who visits the site and selling it when they already charge PornHub good money for a certificate. But who knows?



An eavesdropper would already be able to see this in the sni information.

SNI is even more accurate, because things like cloudflare certs are often for 100s of different domains with many wildcards.

eSNI has not really taken off yet, so almost always your requests are saying the exact domain you are going to in clear text.

However, the bit about the CAs getting some analytics about certs they issue is valid.


OCSP is default enabled in Firefox actually, so you're already doing that.

Setting required to true just makes it actually demand a response instead of allowing an MITM to block it making OCSP ineffective.

At the end of the day we need to start progressively rejecting certificates that aren't OCSP stapled to fix both sides of this, but for now this is the best fix available for technical people who understand how OCSP works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: