Skip to content

Comment on WoSign Incidents Report Update [pdf]parent

Comments

There is a public exception process to handle SHA1 certificates, and for the rest, they get special certificates of old root certificates that are only on older devices.

Obviously, all these options are not available to anyone except a handful of large companies.

That's at best off topic again. We're discussing the actions and trustworthyness of a currently trusted root CA here.

Edit: The exception processes also do not involve fraudulently backdating anything. Which is kind of a big deal when you are in the trust business.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.