3 ms·
> Note that this is the same logic we use for validating TLS certificates, so it’s relatively well understood code that we were able to leverage. Don't know wh
by PudgePacket 7y ago
> Note that this is the same logic we use for validating TLS certificates, so it’s relatively well understood code that we were able to leverage.
Don't know whether to be happy or scared that the TLS validation code is "relatively well understood" :D ! I assume it's just a sub-optimal choice of phrasing.
- josteink 7y agoI’m scared that they (still?) confuse regular HTTPS TLS-validation with code-signing. These are two entirely different domains which follows entirely different rules. Current Firefox behaviour is still broken, even after the “fix”.