TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

HTTPS Is a Privacy Nightmare

5 pointsby paddlesteamerabout 5 years ago

2 comments

cipherboyabout 5 years ago
Doesn&#x27;t Certificate Transparency, OCSP, and CAA help? If the certificate isn&#x27;t in the CT log, the certificate was issued maliciously and won&#x27;t be trusted. If this is truly the case, the CA could revoke it with OCSP checking. And no CA other than the one designated by the site owner is allowed. Then we&#x27;re back to securing DNS. :-)<p>This isn&#x27;t in strict enforcement now, but in a couple of years when browsers have placed enough pressure on CAs, this could be workable and addresses most of the paranoia mentioned in the article.
评论 #22734165 未加载
stevavoliajvarabout 5 years ago
Fair, but what alternatives are there ?
评论 #22734902 未加载