Y
Hacker News
new
|
ask
|
show
|
jobs
by
sugarpimpdorsey
333 days ago
I'm sure those six-day lifetime certificates will work out real nice.
1 comments
ocdtrekkie
333 days ago
I think I am going to become a fan of shorter certificate lifetimes because as soon as the chuckleheads in the CAB truly break the Internet on the level they are pushing for, the sooner we get to discard the entire PKI dumpster fire.
link
NooneAtAll3
333 days ago
what's the alternative to PKI?
link
haiku2077
333 days ago
Certainly something a hell of a lot simpler then x509 - and without assumptions from the 1990s hardcoded into it
link
cpach
333 days ago
Is it really X.509 that is the big “problem”? If so, I fail to see how.
link
greyface-
333 days ago
https://en.wikipedia.org/wiki/Decentralized_identifier
link
jtchang
333 days ago
So basically you trust something because you have a long chain of assurances that you trusted it before? Kinda like certificate pinning.
link
dylan604
333 days ago
no alternative. just eliminate the thing not liked. it's called being DOGEd
link