4 ms·
> Not to mention that "uncovered later" is pretty damn worthless. It is not worthless as a deterrent to the CA. Proof of a fraudulently issued certificate are
by electrum 8y ago
> Not to mention that "uncovered later" is pretty damn worthless.
It is not worthless as a deterrent to the CA. Proof of a fraudulently issued certificate are grounds to permanently distrust the CA. So, yes, they can do it, but hopefully only once.