Hacker News new | past | comments | ask | show | jobs | submit login

Same for any web server unless the app hard-codes a specific certificate. Otherwise any CA can issue a certificate for any domain by default, CT can only catch such a thing after it happens. Don't know if uber.com has CAA records.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: