Y
Hacker News
new
|
ask
|
show
|
jobs
by
bifel
4296 days ago
Is "changing the locks" (revoking the certificate) really so complicated that this "janitor-solution" is easier/cheaper/safer?
1 comments
wsh
4296 days ago
The CA can revoke the certificate, but since revocation checking in browsers is neither universal nor reliable under attack, revocation isn't a completely effective way to recover from a compromised private key.
link