3 ms·
I recently learned in my security class that certificates are the way by which domains are publicly identified. But I don’t understand why there hasn’t been any
by QML 9y ago
I recently learned in my security class that certificates are the way by which domains are publicly identified. But I don’t understand why there hasn’t been any alternatives besides trusting these companies to issue certificates...
- SteveNuts 9y agoIt would be really hard to keep everyone's browsers/operating systems updated with a list of certificates as they're generated and renewed. You pretty much have to concentrate it down to a small subset of trusted certificate authorities to sign your certificate. Also, it should be a way to verify that random people aren't able to get certificates on behalf of a domain they don't own (there's nothing stopping me from generating a cert for google.com - but it should be impossible for me to get it trusted by your browser).