• Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      15 hours ago

      Which nullifies the point of certificates having an expiration date (limited window for exploiting a compromised certificate, possibility of domains changing hands), not the point of validating the signature (tie responsibility for apps to who owned a domain on a specific date, allow third parties to create blacklists of bad developers).