Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
supriyo-biswas
2y ago
0 comments
Share
CA changes can happen due to many legitimate regions. Pinning certificates in this way doesn’t scale, as we saw with the deprecation of HPKP.
0 comments
default
newest
oldest
Jensson
2y ago
All you need is a list of trusted CA's, like we do right now, and then issue a warning if it isn't on that list. It is a very simple plugin to make.
g-b-r
2y ago
These certificate authories
will
also issue legitimate certificates btw, the regulation explicitly encourages local states to use them for their services
j
/
k
navigate · click thread line to collapse