> Possible fake cert for Github https://crt.sh/?id=29647048 https://crt.sh/?id=29805567 > Possible fake cert for Alibaba, the largest commercial site in China https://crt.sh/?id=29884704 > Possible fake cert for Microsoft https://crt.sh/?id=29805555 Yikes. If all of that is true, surely Google will permanently ban WoSign from Chrome? And I would hope Mozilla and Microsoft, too, but Google is usually the one to "play…
Or maybe limit them to certain .cn domains? (Excluding well known targets?)
See:
http://security.stackexchange.com/questions/31376/certificat...
http://blog.codekills.net/2012/04/08/adventures-in-x509-the-...