▲ | cyphar a day ago | |||||||
You could store the certificate hashes in DNS (i.e., use DANE instead of the CA PKI) and so a MITM on the actual connection wouldn't succeed. | ||||||||
▲ | cortesoft a day ago | parent [-] | |||||||
Right, but what if the certificate is compromised? How would your revoke it? | ||||||||
|