Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Certificates don't go with "authors", they go with domains. They are only (!) a promise that some grown up at a cert factory decided that the admin of the host you are connecting to was the proper owner of that domain.

Now sure, there might be value in having per-subdomain certs in wordpress (though that would be rather complicated for wordpress to administer). But there's nothing wrong with that wildcard cert -- it provides proof that you've reached a blog hosted at wordpress, and not a MitM ready to lift your account password when you try to leave a comment.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: