|
|
|
|
|
by ggm
534 days ago
|
|
In my personal QC skeptic opinion, frequent recertification of the site certificate would do for now. We don't need perfect forward secrecy and so future pqc outcomes about decoding packet captures made now seem fruitless for this context. (We don't need pfs because afaik everything here is visible, and individual user logins aren't based on public private cryptography. If the tls cert was rolled every day I wouldn't care) Maybe the cert issuing chain needs to be looked at for its risks but I can't see the site certificate itself being at risk. I mean I am glad cloudflare and others are showing capability but my highly broken foot gun of futurology says to me, this is a fools errand. I've been wrong many many times. |
|
HN is using Let's Encrypt, and so are about a third to half the sites on the internet at this point. If there's an issue with Let's Encrypt, the people on/running this site would know.