Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are much better ways to notify users than trying to convince them of the value of monitoring their bank's CA. The browser could simply keep track of the cert and notify the user if it changes unexpectedly. This doesn't require the user to understand anything new, and it still works in the case that the fraudulent cert is signed by Verisign.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: