Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What attack does that prevent? If the leaf certs are compromised, then so is the server, and it is already game over.


It prevents the attack where thousands of users have thousands of long-forgotten keys lying around, and eventually one of them gets compromised months or years after it was last legitimately used. AKA a huge attack surface that can't reliably be culled, because you are effectively relying on users to be their individual CAs.

This particular attack took down my former organization once.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: