Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I actually agree. They should just yellow bar all the SHA-1 stuff. But will such a subtle approach force CAs to do the right thing? Unfortunately people have been bugging them for a long time, and it seems only a metaphorical gun to their heads has had any effect.

I agree that HTTP being white and "happy" and SHA-1 giving the "DANGER WILL ROBINSON" scare alert, is inconsistent/wrong. That's more a HTTP issue however rather than a SHA-1 one (i.e. HTTP needs to be marked insecure).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: