Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting. Does this mean that - without your Google hat on at least - you would prefer that references to the PSL were removed from the CA/B BRs as well?

WebAuthn ends up relying on the PSL as well (via a concept of "registrable domains" and WHATWG). Presumably you'd want that to just require Same Origin instead?



Yes.

The WebAuthN case in particular is quite unfortunate, and one I tried to discourage early on (along with the whole app facets approach)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: