it seems Firefox started doing the CT validation too, without needing to contact the CT log service: developer.mozilla.org/…/Certificate_Transparency#…
Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative?
IpsumLauren@lemmy.world 2 hours agoOh snap! That definitely sounds possible. Found more info about it.
tl;dr: Either the attack is ineffective against some browsers that check the certificate transparency logs (like Chrome), or the attack is visible and the CA will lose all its credibility (hopefully being removed from the browsers).
WhyJiffie@sh.itjust.works 1 hour ago
WhyJiffie@sh.itjust.works 1 hour ago
and details: wiki.mozilla.org/…/Certificate_Transparency
this sounds important:
this also means, it can’t truly verify SCT’s that were issued since the last browser update?