Hacker News new | ask | show | jobs
by 43920 594 days ago
All of the domains are pointing to the same hosted services run by Firebase, meaning only Firebase themselves has the private key, so the customers whose domains use the certificate shouldn’t be able to MITM anything.

Cloudflare used to do (or maybe still does?) this with their free certificates as well.