Hacker News new | ask | show | jobs
by nsgi 3875 days ago
With the current system, they can just seize the domain and get a certificate for it.
1 comments

No. Seizing the domain does not help them if millions of browsers have the correct certificate pinned.

Meanwhile: we're all pretty unhappy that the USG does just seize domains. How can it possibly be reasonable for us to support a forklift upgrade of a core protocol that burns that capability permanently and cryptographically into the core of the Internet?

Unless you have a short life 90 day cert from LetsEncrypt.org then your pinning doesn't last very long.
I'm not sure what your argument is. Can you restate it?