logoalt Hacker News

sam_lowry_yesterday at 8:00 PM3 repliesview on HN

[flagged]


Replies

schoenyesterday at 10:11 PM

You might want to be more specific about the meaning of "between" here. It's not a cryptographic MITM attack, and if it ever facilitated someone else in performing one, that should be detectable.

https://en.wikipedia.org/wiki/Certificate_Transparency

(It's also true that the level of active monitoring of CT logs has never gotten very high.)

jsheardyesterday at 8:29 PM

It's not like Let's Encrypt is the only game in town, Actalis in Italy provides free ACME certs too if you'd prefer to keep things in Europe.

show 2 replies
charlesbarbieryesterday at 9:20 PM

They are definitively not the most shady organization in the CA/Browser Forum.