On 12 November 2015 at 16:44, Peter Eckersley <p...@eff.org> wrote: > But is 3 the best answer?
Of those presented, I think so. I know that this isn't a great answer (it's bad already, so bad must be OK), but being able to drop things into .well-known opens a raft of other interesting attacks. More seriously, I think that the other options all have deployment complications that far outweigh the marginal benefit that extra checking might provide. _______________________________________________ Acme mailing list Acme@ietf.org https://www.ietf.org/mailman/listinfo/acme