Skip to content

Comment on Client-side SSL/TLS MITM, compromised CA and server impersonation detectionparent

Comments

Certificates could be initially delivered out of band, e.g., in person, or by postal mail. Perhaps in a printed format that can be scanned in.

But then there's no way of telling which postal mail is actually from Google, right? :)

We'll sign the out of band letters with their signing key to prove it's aut- wait. Chicken and egg problem.

Or we could just sign the OOB letters, on company letterhead, with an ink pen.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.