Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
TLS over Tor (ian.sh)
10 points by iancarroll on Oct 31, 2014 | hide | past | favorite | 2 comments


This is sort of obvious. Facebook's key is signed by a well-known CA. Anyone can make a cert for anything, but that doesn't mean that browsers will recognize it as being "valid".

The author fails to mention how this any more "broken" than TLS on anything else.


This is a valid certificate issued by GlobalSign, parse it yourself (the link is in the post)

(well, now revoked, but still...)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: