Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

However in that case it was Comodo that didn't block the compromised private key.


Right. If you read the rest of the thread though you'll see that that's because they're not actually required to check. (Or at least, it's certainly arguable that they're not.) Any other CA could have done the same thing and that would be considered perfectly acceptable behavior per the Baseline Requirements.


I started the thread, I have read it :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: