One of the major issues with web PKI is that any root certificate authority can sign any domain.
For Google this is fixed by hard coding the SSL hashes into chrome, for the rest of us we rely on http headers; which of course are much more fungible.
For Google this is fixed by hard coding the SSL hashes into chrome, for the rest of us we rely on http headers; which of course are much more fungible.
Maybe with DoH it’s better. But that’s more https to make https not suck.
Disclaimer, I didn't know about them either. TIL.