On 12 November 2015 at 16:44, Peter Eckersley <p...@eff.org> wrote:
> But is 3 the best answer?

Of those presented, I think so.  I know that this isn't a great answer
(it's bad already, so bad must be OK), but being able to drop things
into .well-known opens a raft of other interesting attacks.

More seriously, I think that the other options all have deployment
complications that far outweigh the marginal benefit that extra
checking might provide.

_______________________________________________
Acme mailing list
Acme@ietf.org
https://www.ietf.org/mailman/listinfo/acme

Reply via email to