Hacker News new | past | comments | ask | show | jobs | submit login

WoSign was also caught red-handed backdating certificates to avoid the SHA1 deprecation.

So you can't trust that information either. As mentioned in a different thread, whitelisting certificates extracted from CT logs is the only really viable choice here.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: