| ▲ | Borealid 3 hours ago | ||||||||||||||||||||||
This sounds like something that HPKP ( https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning ) could have prevented and CAA records ( https://letsencrypt.org/docs/caa/ ) could not. But HPKP is deprecated. | |||||||||||||||||||||||
| ▲ | airza 27 minutes ago | parent | next [-] | ||||||||||||||||||||||
The problem is that there is no out-of-band mechanism for update like other devices. If your CA certs are bad on your mobile application, you can push an out-of-band update via the device's app store. If your CA certs are bad on a website you access via your browser, the means of updating them is... the browser. You can't get new certs without using a TLS connection you didn't want to trust anyway. | |||||||||||||||||||||||
| ▲ | w3ll_w3ll_w3ll 33 minutes ago | parent | prev [-] | ||||||||||||||||||||||
CAA records (with ACME account bindings) can prevent this. HPKP was deprecated because it was too dangerous to be deployed in production. | |||||||||||||||||||||||
| |||||||||||||||||||||||