Comment on Google's plan to restrict sideloading on Android has a potential escape hatch for users

<- View Parent
InnerScientist@lemmy.world ⁨2⁩ ⁨days⁩ ago

Doesn’t work, the reason they can expire is to make certificate rotation possible. If an expired ssl certificate is cracked it doesn’t matter because no browser will accept the expired certificate, with your idea the expired certificate just signs an app with the date of 1984 and it works.

Certificates in SSL can’t change the date because that date is signed by a certificate higher in the hierarchy.

source
Sort:hotnewtop