logoalt Hacker News

CommanderDatalast Thursday at 5:27 PM1 replyview on HN

Isn't certificate transparency opt-in, so any trusted CA could be a potential attack route.


Replies

JoshTriplettlast Thursday at 5:56 PM

Browsers now require it to consider a certificate valid. Firefox, Chrome, and Safari all require a certificate to include proof of being logged in CT logs.