Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's enforceable because any such fraudulent certificate, once found, identifies both the dodgy intermediate CA and the responsible root CA. The fraudulent cert itself provides all the proof that Mozilla needs to revoke the corresponding root.

The fraudulent certificates could be found and saved by a user using Chrome's certificate pinning feature, or Firefox's Certificate Patrol add-on, or similar.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: