Remix.run Logo
▲ mattashii an hour ago

> The browser would be able to take policy of simply never trust a certificate whose signer has changed

This assumes that the signer's keys can't be compromised, and re-introduces the issues of key pinning that the WebPKI community has been pushing very hard to eliminate from its dependents. I don't think it's a workable solution.