Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you look at Chrome's change to https indicators, they give these sites with auto issued certs the lock so users will interpret it as "secure". Seems easy to create fraud sites and give them a legitimate site look.


Also discussed at

https://community.letsencrypt.org/t/the-cas-role-in-fighting...

which is the official discussion thread for Josh's article on this topic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: