

2·
6 days agoThat would be just a nuisance until a new certificate is generated with another vendor (possibly not for free, but cheap enough).


That would be just a nuisance until a new certificate is generated with another vendor (possibly not for free, but cheap enough).


It opens the possibility of a man-in-the-middle attack.


First let’s identify what parts of the world are free-er than the US (for a certificate).
Oh snap! That definitely sounds possible. Found more info about it.
tl;dr: Either the attack is ineffective against some browsers that check the certificate transparency logs (like Chrome), or the attack is visible and the CA will lose all its credibility (hopefully being removed from the browsers).