Hacker News new | ask | show | jobs
by Nightshaxx 2049 days ago
The idea that sending information about the cert is somehow not exposing the app is crazy. An attacker could easily download apps and sniff the network traffic to correlate cert info with an app.

Also i don't get the argument for using HTTP. Aren't these two separate systems?