logoalt Hacker News

xg15yesterday at 10:43 PM2 repliesview on HN

How is "client certificates forbidden" in any way an improvement?


Replies

bawolfftoday at 5:40 AM

As a general rule in cryptography, a lot of vulnerabilities relate confusing the system by using a correct thing in the wrong context. Making it a rule that you have to use separate chains for separate purposes is a good rule from a general design standpoint.

show 1 reply
Avamanderyesterday at 11:30 PM

Not forbidden, just not going to be a part of WebPKI.

It's one of those things that has just piggybacked on top of WebPKI and things just piggybacking is a bad idea. There have been multiple cases in the past where this has caused a lot of pain for making meaningful improvements (some of those have been mentioned elsewhere in this thread).

show 1 reply