3 ms·
> though it smells like the opposite of responsible disclosure He's not sharing the key itself, just proof that it's been leaked. Unlike disclosing a security
by profmonocle 3y ago
> though it smells like the opposite of responsible disclosure
He's not sharing the key itself, just proof that it's been leaked. Unlike disclosing a security issue without warning, this disclosure doesn't give any bad actors and power they didn't already possess. (Because any bad actors who have the key would already know what TLS certs it matches, or could trivially find out by querying CT logs themselves.)
- hunter2_ 3y agoThank you!
- hsbauauvhabzb 3y agoEven with the key, from what I can tell it’s fairly hard to exploit for the average netizen.