| ▲ | CommanderData 4 days ago | |
Isn't certificate transparency opt-in, so any trusted CA could be a potential attack route. | ||
| ▲ | JoshTriplett 4 days ago | parent [-] | |
Browsers now require it to consider a certificate valid. Firefox, Chrome, and Safari all require a certificate to include proof of being logged in CT logs. | ||