Earlier quoted context omitted.
> Certificate Transparency is a solution CT would not have prevented these attacks. Google would be exactly where they are right now: knowing who issued cert, and that's it. Short form: https://github.com/okTurtles/dnschain/blob/master/docs/Compa... Long form: https://blog.okturtles.com/2014/09/the-trouble-with-certific... (EDIT: How about an honest discussion instead of a downvote? If you disagree, you are welcome t…
Given the operational difficulty of implementing a transparently-MITMing proxy in a Certificate Transparency regime, I'm not sure you can say with certainty that it wouldn't have prevented this attack. Every time you want to MITM a new site, you need to contact some number of auditors before you can complete the connection. That sounds difficult to implement reliably and quickly enough for a MITM to work. (Not to men…
To add on to this: the certificate was generated from a Palo Alto Networks device.
https://groups.google.com/forum/#!topic/mozilla.dev.security...
If Palo Alto aren't willing to implement CT, which I'm pretty sure they aren't because they're a legitimate company whose business isn't driven by people who abuse globally-valid certificates, then (regardless of whether SCTs can be forged in theory) that alone would have prevented the attack.