7 ms·
> Case 1 is moot, case 2 would be prevented by properly implemented HTTPS. That's not true. It's significantly easier to ensure the security of an offline sign
by oconnore 3y ago
> Case 1 is moot, case 2 would be prevented by properly implemented HTTPS.
That's not true. It's significantly easier to ensure the security of an offline signing key than it is to ensure that an arbitrary HTTPS server avoids ever becoming compromised.