←back to thread

482 points sanqui | 2 comments | | HN request time: 0.417s | source
Show context
cjalmeida ◴[] No.42285429[source]
It gets worse. ICP-Brasil, the AC mentioned in the bug reports, the the government run agency responsible for all things related to digital signatures. Digitally signing a contract, a deed, accessing tax returns…
replies(2): >>42285683 #>>42286883 #
layer8 ◴[] No.42285683[source]
Unlike web browsers, digital signature use cases should perform revocation checks, so revoking the google.com certificate should solve that.
replies(3): >>42285783 #>>42285825 #>>42292286 #
perching_aix ◴[] No.42285783[source]
I think the current "meta" is CAA records? https://blog.cloudflare.com/why-certificate-pinning-is-outda...
replies(2): >>42285927 #>>42292557 #
1. syncsynchalt ◴[] No.42292557[source]
CAA records rely on the CAs to respect them, and this is an article about how a CA has issued a cert in violation of a CAA record.
replies(1): >>42292602 #
2. perching_aix ◴[] No.42292602[source]
Oh right, for some reason I was under the impression that browsers utilize the record too.