logoalt Hacker News

mattashii • today at 9:44 AM • 0 replies • view on HN

> The browser would be able to take policy of simply never trust a certificate whose signer has changed

This assumes that the signer's keys can't be compromised, and re-introduces the issues of key pinning that the WebPKI community has been pushing very hard to eliminate from its dependents. I don't think it's a workable solution.