Hacker News new | ask | show | jobs
by tremon 1387 days ago
Every escape hatch in the certificate validation is also an additional avenue for attack. For example, using a DNS record to override certificate pins makes DNS cache poisoning much more valuable to the attacker.
2 comments

Every layer of security is also an additional accessibility hurdle.
Got it, thanks @tremon.