Hacker News new | ask | show | jobs
by jimrandomh 5613 days ago
The point of collecting payment for certificates is not that attackers can't afford it, but that it enables the CA to do some cursory verification, and creates a trail of evidence if the certificate is used for a scam later.