Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think you understand what the code is doing.

This is verifying certificates for HTTPS connections - not creating them. If they removed the SHA1 verification, you can no longer visit hundreds of millions of sites that haven't updated their certificates yet.

It's the people still using certificates with SHA1 hashes that need to upgrade.



But if browser makers decided not to support the hashes, the website owners would have to upgrade. Why allow them to continue to use weak hashes?


Because there isn't an attack that affects them.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: