|
|
|
|
|
by JoshTriplett
3527 days ago
|
|
The logs don't necessarily have to be public; they just have to be accessible to the browsers browsing sites using those certificates. Requiring CT universally, even for "private" CAs, provides detailed evidence for several kinds of problems, such as various laptop vendors who have pre-installed MITMing proxies. It doesn't prevent those kinds of behaviors, but it makes denials less credible. |
|
When a laptop vendor is building the device that's being shipped, I don't think it's practical for a browser vendor to be able to expect to win that arms race.