Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is the real issue with not allowing wildcard certs. If the rate limits were something that just cut in at abuse-levels, there'd be no need for them. Sites with per-user subdomains (to get security features like cookie isolation, break same-origin effects, etc) run into the limits really quickly, and must currently rely on a wildcard.

I've been calling this "the tumblr scenario", but people seem to think there's a way around it without just using another CA.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: