Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, not at all. That's not how SSL certificate revocation works.

If the certificate is not revoked when compromised, the party harmed may not be the StartCom customer, but anyone still trusting certificates issued by them.

When this is happening on a large scale, considering the CA status of StartCom is certainly due dilligence.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: