@whispersystems Hey, you ARE pinning the flock TLS cert right? Also you should fix the rest of this stuff https://www.ssllabs.com/ssltest/analyze.html?d=flock-sync.whispersystems.org&s=54.244.91.66&latest …
-
-
Replying to @kyhwana
@kyhwana Ugh, for apps@whispersystems controls, why is most of that even ON?! Twisted defaults? Also, WTF 27-year SHA1 certificate?3 replies 0 retweets 0 likes -
Replying to @sindarina
@sindarina The server is its own authority. Makes no difference what the sig hash is or how long the expiration is.@kyhwana2 replies 0 retweets 0 likes -
Replying to @signalapp
@whispersystems I beg to differ; there is no reason to use a SHA1 certificate nowadays, use SHA2. If only for perception.@kyhwana2 replies 0 retweets 0 likes -
Replying to @sindarina
@whispersystems Two, long duration self-signed means you have no way to revoke if the key is compromise. Expiration is a backup.@kyhwana2 replies 0 retweets 0 likes
@sindarina That's not how revocation works. The only reason you see short expiration on the web is so CAs can make money. @kyhwana
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.