Hacker Newsnew | past | comments | ask | show | jobs | submit | kedihacker's commentslogin

They can do this with certificate transparency other wise CA can sign whatever date they want. But if they collude with CT that can issue rouge certificates for targeted attacks.

Yes, that's all right, there's already a requirement that they submit to one Google CT log and one non-Google CT log. They thought about it already. The playbook I mentioned they've been rehearsing contains specific threat against backdating certs, they say they'll distrust immediately if they detect, and they have means of detecting backdating on significant scale (esp. for LE, where they submit 100% issued certs, not just the subset that is intended for consumption with Chrome).

Well you need to stop them from getting incorporated into its training data


Only us east 1 gets new services immediately others might do but not a guarantee. Which regions are a good alternative


Well letting tb evolve over time and infect everyone is a lot more dangerous


Well microcontrollers can prevent you from repairing your own device with DRM and secure enclaves


They have placed different data centers very close so it might not be enough


Guess that is why bigger clouds cost more. Partly! No free lunch.


Or you can use a more reliable host like Hetzner.


it is reliable until they decide to close your account for no reason


I hear stories like this on every provider.


Google doesn't know it only sees a happy user


It would be perfect upsell for Atlassian because of their products abysmal performance of their product.


Well it can be bypassed by setting up a new company with the same name. Someone had done that against stripe I remember.


EV certs show the company name and the country, for disambiguation, on the assumption that you cannot have two companies of the same name in the same country. However, this is not true in the USA, where names are unique only within each state.

That's how someone got an EV cert for Stripe (USA).


Support would be a big part of the enterprise and smaller ones pie but at 47 days everything would be integrating acme protocol so rough times ahead


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: