Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The main EFF contribution to this problem right now is the SSL Observatory.

https://www.eff.org/observatory

You can allow your copy of HTTPS Everywhere to send us certs, which can help researchers understand what CAs are doing and potentially detect misissued certs.

Two other important mechanisms are Certificate Transparency and HPKP.

http://www.certificate-transparency.org/

https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning

The former is a way -- I hope! -- to eventually require the open publication of all issued certs that the public is expected to trust. The latter is a way for sites that you successfully connect to at one point to prevent other CAs that they don't have any relationship with from helping to MITM your future connections.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: