Hacker News new | ask | show | jobs
by vertex-four 4398 days ago
> For example, they refused to reissue certificates for free after Heartbleed.

Not only that, but I believe they refused to revoke the certificates in the first place without payment. So if you don't pay up, even if you go buy a certificate from someone else or decide to use self-signed certificates, an attacker could still use your old certificate to MITM your website.