Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even then, use of a DNS CAA record should mitigate this, right?


Maybe?

I wouldn't assume that the bug doesn't bypass CAA checking.

Very important question to answer.


Yeah - unless you're an actual SSL.com customer, in which case your CAA records would allow it. That's a much smaller blast radius at least.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: