3 ms·
Too big to fail: It's not just for banks any more. If LE is compromised a few times and some fraudulent facebook.com or google.com certs leak out, how long bef
by user1980 7y ago
Too big to fail: It's not just for banks any more.
If LE is compromised a few times and some fraudulent facebook.com or google.com certs leak out, how long before Firefox/Chrome/Edge blacklist their root cert like they did with Symantec[1], and end up breaking half the internet?
I understand that ACME is an open standard, but can someone point me to an alternative ACME provider that isn't "please call us for a quote" enterprise-grade?
[1]: https://blog.mozilla.org/security/2018/03/12/distrust-symantec-tls-certificates/ https://blog.mozilla.org/security/2018/03/12/distrust-symant...
- move-on-by 7y agoSeems like a reasonable fear, but it is mitigated by short certificate lifespans. Symantec was much more painful to distrust due to multi-year certificate lengths.