TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: etc./letsencrypt/ had past five years of data

1 点作者 unlog大约 4 年前
Had to look by chance at that folder and found out the full history of certificates and keys were sitting there. I don't know what to think, isn't this like having a record of all your previous passwords?, but worse.

1 comment

noodlesUK大约 4 年前
It’s not nearly as bad as you think. If you’re a Let’s Encrypt user, there’s a high likelihood that your servers (and your clients) were negotiating PFS cipher suites.<p>If they were, a compromise of the private key wouldn’t mean that you could break past intercepted communications.<p><a href="https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Forward_secrecy" rel="nofollow">https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Forward_secrecy</a>
评论 #26968665 未加载