Hacker News new | ask | show | jobs
by wsh 4296 days ago
The CA can revoke the certificate, but since revocation checking in browsers is neither universal nor reliable under attack, revocation isn't a completely effective way to recover from a compromised private key.