Hacker News new | ask | show | jobs
by nonuby 4130 days ago
Following the chain, "Any superfish engineers here? Do you think you could of mitigated a large amount of this PR hell (not that it makes it okay) by generating a random root-cert per install, and refusing to accept it on the WAN side of the proxy?" (I guess like AV software does). What was the motive for 1 static cert?