22 karma · joined August 1, 2024
If we were able to guarantee NO certificate authorities used WHOIS, this vector would be cut off right?
And is there not a way to, as a website visitor, tell who the certificate is from and reject/distrust ones from certain providers, e.g. Digicert? Edit: not sure if there's an extension for this, but seems to have been done before at browser level by Chrome: https://developers.google.com/search/blog/2018/04/distrust-o...
- Be inherently less trustworthy of more unique TLDs where this kind of takeover seems more likely due to less care being taken during any switchover.
- Don't use any "TLS/SSL Certificate Authorities/resellers that support WHOIS-based ownership verification."
https://i.imgur.com/ZNv1AyD.jpg
Could it change? Maybe. But right now Tesla is the most popular EV in the US and Europe.
My HelloWorld program also has higher performance and lower memory usage than SpringBoot. Rust moment.