Hacker News new | ask | show | jobs
by anticristi 2258 days ago
Well, you could use HTTP over an IPSec tunnel with a pre-shared key (obviously distributed face-to-face), and that would have been resistant to a CA being hijacked.

However, nowadays, I believe with CT HTTPS is really safe. But again, someone had to nitpick on the security limitations of HTTPS for CT to be invented.