I liked the CA MITM call out.. we just trust these organizations to not deploy wildcard malicious certificates.
Kinda messed up devices come preloaded with unchangeable trusted CAs
Guy knows his stuff, also works for dod.
Kinda messed up devices come preloaded with unchangeable trusted CAs
Guy knows his stuff, also works for dod.
Don't we have transparency logs to check that now?
(in memory of Douglas Adams)
It's this one. https://bugzilla.mozilla.org/show_bug.cgi?id=505521
RunSet™: Install everything everywhere all at once.
[Donate]
They don't actually go check and compare the embedded SCT with what is in the logs. It would be incredibly slow to load the site if they did that.
It's not clear to me how you know who asked for the certificate in the log. Do you somehow compile the private keys of all entities that are allowed to request certificates and compare that to the CTL?