3 ms·
In practice I found new certs being available for download from CT logs hours after they've been issued. This is more than enough to perform an attack. Another
by pjf 7y ago
In practice I found new certs being available for download from CT logs hours after they've been issued. This is more than enough to perform an attack.
Another point is that CTs alone won't prevent the attacks nor inform you about a problem - they need a monitoring system.
(yes I know that's not the problem with CT - it's great, just trying to justify a strong opinion of "it doesn't work")