Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those are not comparable. For better or worse, the attacks you speak of are not covered by DV's threat model, and all DV-issuing CAs--not just Let's Encrypt--suffer from them.

The Startcom vulnerabilities, on the other hand, are much easier to exploit and clearly violate DV's threat model.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: