Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to and
It's how nearly everything works, and even systems like Domain Validation certificates are basically just delegated TOFU. We not only trust all these CAs but also rely on an attacker not doing a MITM of the initial verification by the CA, with only CAA as a way to mitigate that.