Hacker News new | ask | show | jobs
by elp 303 days ago
Unless I'm completely misunderstanding things Letsencrypt has been doing this since 2020 https://letsencrypt.org/2020/02/19/multi-perspective-validat...

I.e they check from multiple network locations in case an attacker has messed with network routing in some way. This is reasonable and imposes no extra load on the domain needing the certificate all the extra work falls on the CA, and if Letsencrypt can get this right there is no major reason why "Joe's garage certs" can't do the same thing.

This is outrage porn.