• Redex@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      1 day ago

      From what I see in the article it seems it’s a classic case of Croatian public sector IT being incompetent. But it doesn’t seem to be that big of an issue. They were only created for internal testing and were immediately revoked. It’s still not good, but the opportunity for exploit here to me seems extremely low.

    • Cheradenine@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      CAs are like BGP, it’s trust me bro all the way down

      the case demonstrates the “single point of failure” vulnerability in the certificate authority ecosystem