2016-09-01
Schrauger.com
How WoSign, a Chinese CA, issued a valid SSL cert for GitHub's primary domain to a subdomain user, and didn't revoke it even after vulnerability was reported
Stephen Schrauger / Schrauger.com : Tweets: @filosottile , @returnstring , @kennwhite and @juliocesarfort Tweets: Filippo Valsorda / @filosottile : I untrusted the WoSign root, well prepared to some ...
Loading articles...