Remix.run Logo
▲ Borealid 3 hours ago

This sounds like something that HPKP ( https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning ) could have prevented and CAA records ( https://letsencrypt.org/docs/caa/ ) could not. But HPKP is deprecated.

▲airza 27 minutes ago | parent | next [-]

The problem is that there is no out-of-band mechanism for update like other devices.

If your CA certs are bad on your mobile application, you can push an out-of-band update via the device's app store.

If your CA certs are bad on a website you access via your browser, the means of updating them is... the browser. You can't get new certs without using a TLS connection you didn't want to trust anyway.

▲w3ll_w3ll_w3ll 33 minutes ago | parent | prev [-]

CAA records (with ACME account bindings) can prevent this.

HPKP was deprecated because it was too dangerous to be deployed in production.

▲iso1631 28 minutes ago | parent [-]

Not when you simply remove the CAA record from the DNS entry

▲ 2 minutes ago | parent | next [-]
[deleted]
▲w3ll_w3ll_w3ll 2 minutes ago | parent | prev [-]

That is a good point.