Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can anyone find the link to that recent article / guide on registering a likely-looking address at a webmail provider then scamming a root certificate for that domain?

The article gave the impression that some CA's are a bit too happy to issue root certs, and he mentioned he's been blogging about the whole SSL trust system being broken for quite a few years now.




Nice one, thanks.


+1

I would apreciate this article too! issueing a root cert at mozilla isn't as easy as it looks... they changed a lot in the process i think




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: