Hacker News new | past | comments | ask | show | jobs | submit login

It's obvious that your straw man has no clue how SSL works. Why should the disclosure of one SSL key compromise all users of your service?



Because an SSL certificate is linked to a specific domain. It has nothing at all to do with user accounts. Creating a custom domain for each and every user is totally nonsensical from both a business and technical standpoint.


God did not say "Lavabit must only use SSL and cannot use any other measures to fulfill its understood and contractual obligations with customers". That is ridiculous.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: