Skip to content

Comment on Revocation still doesn't work

Comments

Someone should set up a bet about what point in time more than 50% of MITM attempts with revoked (& Heartbleed-snarfed) certs will be caught by default configured browsers. "Never?"

This and lack of PFS are much bigger catastrophes than the OpenSSL debacle in itself.

(PFS: supported by TLS but disabled by almost everyone so all your old traffic is decryptable with heartbled cert).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.