Certificate transparency makes issuance observable
Every publicly trusted certificate is now logged where anybody can read it.
That turns a silent problem into a visible one. If somebody obtains a certificate for your domain that you did not ask for, it appears in the logs, and you can be alerted. It does not prevent misissuance, it makes it detectable, which historically was the harder problem because organisations had no way of knowing it had happened.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- DNSSEC signs answers but does not hide themA sealed postcard
- Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
- Registrar compromise can outrank server securityIt all hangs from one fitting
- Registrar locks add friction to domain theftThe pin that makes them stop
- Dangling DNS can point to somebody else's resourceYour plate, their locker
