Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Small nitpick: Chrome implements CT for all certificates and shows its status, however they only currently plan to downgrade an EV certificate to a normal certificate.

Firefox has an open bug for implementation[1] but it's inactive for whatever reason.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=944175



but it's inactive for whatever reason

Not hard to see why from your explanation.

You don't need implementation in the browser. You need the CAs to provide the public audit logs and all HTTPS domain owners to check them for unexpected issuance.

The browser is just a political tool to enforce the CAs to provide the logs, for example by no longer marking their certs as trusted unless they do so.


If the browser trusts certificates that aren't in the log, then what's the point of having the log at all?


There is none, which is why I said the browser is just a tool in a politics game. It enforces the existence of the log. The security doesn't come from checking whether the cert is in the log!


Which is exactly why the browsers should do just that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: