Hacker News new | past | comments | ask | show | jobs | submit login

Wait... How does letsencrypt know who is giving them the public key cert?



Presumably they can then confirm that the public key matches the certificate that's currently on the webpage.

Unless someone successfully preforms a MITM attack on letsencrypt but then all bets are off.


Given that this article is about mitigating the risk of someone doing precisely that, i don't think "all bets are off" is a good position to take on that scenario.

To summarize TFA: lets encrypt is now verifying domain ownership from multiple data centers. The idea being if someone tries to mitm the verification process (through bgp hijacking or whatever) its much harder to do that across the entire internet and go unnoticed then it is to do it on just one network path




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: