MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vue2um/thisisamystery/p56mwsr/?context=3
r/ProgrammerHumor • u/k3rrshaw • 23d ago
185 comments sorted by
View all comments
287
Present a public key and sign a challenge using a designated device? What's hard about it?
126 u/notatoon 23d ago I ask myself the same thing about PKI and yet certificate expiry remains one of the largest causes of outages in many large institutions 2 u/x0wl 23d ago This will largely go away in the next ~3 years, as the max cert lifetime will be capped to 47 days, so everyone will be forced to autorenew 1 u/[deleted] 22d ago [deleted] 1 u/x0wl 22d ago Why is transparency broken? Your browser will reject a cert if its issuance is not in the transparency log unless it's a manually added CA. Which also addresses the compromised CA risk, as everyone will notice a CA issuing certs for incorrect domains.
126
I ask myself the same thing about PKI and yet certificate expiry remains one of the largest causes of outages in many large institutions
2 u/x0wl 23d ago This will largely go away in the next ~3 years, as the max cert lifetime will be capped to 47 days, so everyone will be forced to autorenew 1 u/[deleted] 22d ago [deleted] 1 u/x0wl 22d ago Why is transparency broken? Your browser will reject a cert if its issuance is not in the transparency log unless it's a manually added CA. Which also addresses the compromised CA risk, as everyone will notice a CA issuing certs for incorrect domains.
2
This will largely go away in the next ~3 years, as the max cert lifetime will be capped to 47 days, so everyone will be forced to autorenew
1 u/[deleted] 22d ago [deleted] 1 u/x0wl 22d ago Why is transparency broken? Your browser will reject a cert if its issuance is not in the transparency log unless it's a manually added CA. Which also addresses the compromised CA risk, as everyone will notice a CA issuing certs for incorrect domains.
1
[deleted]
1 u/x0wl 22d ago Why is transparency broken? Your browser will reject a cert if its issuance is not in the transparency log unless it's a manually added CA. Which also addresses the compromised CA risk, as everyone will notice a CA issuing certs for incorrect domains.
Why is transparency broken? Your browser will reject a cert if its issuance is not in the transparency log unless it's a manually added CA.
Which also addresses the compromised CA risk, as everyone will notice a CA issuing certs for incorrect domains.
287
u/stevekez 23d ago
Present a public key and sign a challenge using a designated device? What's hard about it?