Hacker News new | past | comments | ask | show | jobs | submit login

Do browsers tell you about certificate reissues by default?



No, but they don't have to because (the vast majority of) users don't establish trust in website's TLS certificates themselves; instead, they use a trusted third party: the set of all trusted certificate authorities in their browser or operating system's root store. End-to-end encrypted messengers like Signal and WhatsApp don't rely on a trusted third party to establish trust, instead (rightly) leaving it up to users to establish trust between each other.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: