Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Especially when we have TLDs for this purpose (.test and .invalid), it's just plain sloppy.


CAs would not be allowed to use those TLDs under the current rules. They have two options for testing:

1. Use domains they own.

2. Use a testing environment that doesn't issue publicly-trusted certificates.


> * it's just plain sloppy*

Sloppy is an oopsy. This is negligence.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: