Hacker News new | ask | show | jobs
by g_p 1532 days ago
Some platforms may have a way to remember a client certificate as a preference, but you can't really bind a certificate to only specific sites.

If you can find a way to abuse a valid authentication to one site in order to gain access to another site, that sounds like a very firmly valid security issue needing investigated.