|
|
|
|
|
by bsaul
4131 days ago
|
|
I could see another weaker but immediately implementable approach to just issueing a list of domain-root certificate maps that someone would have to manage : Why couldn't browser issue a warning whenever the root CA for a known domain has changed compared to previous browsing sessions ?
I suppose MITM attack are targeted and probably depends on the network you're using. If there's a difference between the root certificate for google.com when surfing with your laptop at home or from the office, then there's probably something wrong. It's a bit similar to what ssh is doing with cert/ip associations. |
|
http://tools.ietf.org/html/draft-ietf-websec-key-pinning-12