3 ms·
They don't want the extra weak spot of certificate revocation being abused against them? Though I'm not sure how big of an issue this is; sci-hub is using http
by generationP 6y ago
They don't want the extra weak spot of certificate revocation being abused against them?
Though I'm not sure how big of an issue this is; sci-hub is using https.
- jdu9 6y agoUnless they activate HSTS, it shouldn't be a problem. They can always go back to HTTP if they want. Also, Let's Encrypt doesn't even revoke certificates for malware and phishing sites. [1] Maybe they're doing this for better caching performance? It makes SSL flood attacks impossible, but is that really worth it? [1] https://community.letsencrypt.org/t/how-to-report-abuse/41106/4 https://community.letsencrypt.org/t/how-to-report-abuse/4110...