|
|
|
|
|
by michaelt
1119 days ago
|
|
If you are able to compromise a CA and generate a bogus certificate, why couldn't you also compromise a certificate transparency log provider and generate a bogus signed merkle hash? (Not that I'm a DNSSEC user myself, my feet aren't bulletproof) |
|