4 ms·
> I don't know of any issuer key compromises detected with CT. Such compromises are rare. DigiNotar is an obvious example, but can you think of any recent ones?
by bren2013 8y ago
> I don't know of any issuer key compromises detected with CT. Such compromises are rare. DigiNotar is an obvious example, but can you think of any recent ones?
Not key compromise, but general mis-issuance:
Facebook detected overreach by a vendor with CT: https://www.facebook.com/notes/protect-the-graph/early-impacts-of-certificate-transparency/1709731569266987/ https://www.facebook.com/notes/protect-the-graph/early-impac...
AGL detected certs that were malformed in various ways: https://www.imperialviolet.org/2013/08/01/ctpilot.html https://www.imperialviolet.org/2013/08/01/ctpilot.html
> Technically CT is still not required.
It produces an interstitial, see: https://invalid-expected-sct.badssl.com/ https://invalid-expected-sct.badssl.com/