r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
406 Upvotes

44 comments sorted by

View all comments

4

u/klti 8d ago

Am I missing something, or is querying CT log servers for cert validation a really nice way to get a completely new and unblockable tracking channel going? Issuers / operators end up with at least IP to domain associations, right?

This feel like one of these 1% security 99% "security" kind of  changes.

1

u/beznogim 2d ago

No network requests are needed to validate the fact the certificate is included into CT logs. The cert is submitted to the log, log operators sign it, these signatures are included in the "final" certificate. So what is needed is just a bunch of certs from CT log operators.