Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In fact that is how they detected an intrusion in one of the other Root CAs

I know that and that's great, but why only Google? Sure it is Chrome we're talking about, but it is still a mainstream browser. They could make it a bit more neutral by including, say, https-enabled sites from the Alexa top 10k.

> This isn't really intended for the end user to use.

Of course, what I meant was how small websites will get their sites secured. Do we have to do a pull request for every browser out there every time we order a new certificate? It doesn't seem manageable for the developers nor the browser builders.



Well nothing is stopping a top site from changing their Root CA, so it would be impossible to ship pinned certificates without coordination between Google and the site.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: