zlacker

[parent] [thread] 0 comments
1. brazzy+(OP)[view] [source] 2023-05-05 21:26:42
How does the CA get the registrar's public key in a way that cannot be spoofed or hacked like you say DNS and HTTP verification can? If your thread model already includes hacking a CA's network infrastructure, getting them to accept the wrong key as valid doesn't seem any more difficult than the others.
[go to top]