TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

HTTPS Is a Privacy Nightmare

5 点作者 paddlesteamer大约 5 年前

2 条评论

cipherboy大约 5 年前
Doesn&#x27;t Certificate Transparency, OCSP, and CAA help? If the certificate isn&#x27;t in the CT log, the certificate was issued maliciously and won&#x27;t be trusted. If this is truly the case, the CA could revoke it with OCSP checking. And no CA other than the one designated by the site owner is allowed. Then we&#x27;re back to securing DNS. :-)<p>This isn&#x27;t in strict enforcement now, but in a couple of years when browsers have placed enough pressure on CAs, this could be workable and addresses most of the paranoia mentioned in the article.
评论 #22734165 未加载
stevavoliajvar大约 5 年前
Fair, but what alternatives are there ?
评论 #22734902 未加载