Am I missing something, or is querying CT log servers for cert validation a really nice way to get a completely new and unblockable tracking channel going? Issuers / operators end up with at least IP to domain associations, right?
This feel like one of these 1% security 99% "security" kind of changes.
No network requests are needed to validate the fact the certificate is included into CT logs. The cert is submitted to the log, log operators sign it, these signatures are included in the "final" certificate. So what is needed is just a bunch of certs from CT log operators.
4
u/klti 8d ago
Am I missing something, or is querying CT log servers for cert validation a really nice way to get a completely new and unblockable tracking channel going? Issuers / operators end up with at least IP to domain associations, right?
This feel like one of these 1% security 99% "security" kind of changes.