Conversation:
Notices
-
kat (boneidol)'s status on Thursday, 08-Jan-2015 16:09:40 EST
kat
But how do you validate the certificate in a cryptographically secure way ? Do you verify certificate fingerprints out of band with the service provider ? or Trust On First Use (TOFU) as @navigium suggests. Self signed protects against a passive a… -
kat (boneidol)'s status on Thursday, 08-Jan-2015 16:11:06 EST
kat
I mean this validation question is the key question we are trying to solve! I don't know what the right answer is.
-