Hacker News new | ask | show | jobs
by 0xbadcafebee 1932 days ago
But this is vulnerable to a number of attacks that my solution isn't. Right now it's pretty damn easy to create valid certs for arbitrary domains. I'm constantly surprised that nobody wants to fix this.