Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It won't ignore issues for when the CA chains back to a OS preloaded one (when there is a distinction between user-added and preloaded, not sure in other case. ie Linux.) I agree somewhat more could be done on this front however if you're in a position where an adversary can add user-added CA's to your system you have bigger problems to worry about.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: