Hacker News new | ask | show | jobs
by mlyle 597 days ago
SSL/TLS/etc are libraries, yes. And the certificate store is an OS service.

Ancient software has trouble talking to modern services; modern services and devices don't want to fall back to speaking the old versions because of downgrade attacks.

And if you have an important CA certificate expire, you can't talk to anything.