|
|
|
|
|
by dc352
3526 days ago
|
|
So do you imply that the account key is created from scratch for every new certificate? Why we were surprised (and we don't say the implementation is necessarily wrong!) is that I can use the account key anywhere. If the genuine user keeps refreshing authz's, it will keep the stolen account key operational as well. That's my understanding. I may be wrong, but if so, I don't quite yet understand the logic behind authz. |
|
Think of it like the credentials for a hosting provider where you bought your traditional SSL certificate being stolen. Not really a new threat.