6/14/2026 at 3:07:41 PM
Anyone else got a really weird Chorme pop-up asking which cert to use for su3.io:443?Very bizarre, never seen that before.
Thumbprints:
- 60949a09aab8677f87a0b9eda7099a03ca510fb3
- 1b146798f0dc93773247e86312f1b730c4eeebb3
by 1a527dd5
6/14/2026 at 4:09:35 PM
> Very bizarre, never seen that before.For my own stuff that's not meant for a wider audience, I sometimes use mTLS in front of my apps, alongside self-signed certs (my own CA) that shouldn't show up in certificate transparency logs.
This site also seems to be requesting a certificate from the user. Normally you probably don't want that for public facing resources.
by KronisLV
6/14/2026 at 3:58:59 PM
Here it attempts to read my personal certificate that sits in the browser that I use for filling my taxes and do government stuff, suspicious indeed.by embedding-shape
6/14/2026 at 4:47:39 PM
That’s likely just the side effect of supporting mtls. Mutual TLS came around at the same time as Microsoft did implicit network auth. Seemed magical at the time and so hare brained for eons of problems. The user side tls never caught on in most circles and still has the ancient sharp edgesby cmgbhm
6/14/2026 at 4:48:13 PM
That's because the client certificate interface in browsers is supremely dumb. It always just lists all certificates you have, with very little context in the UI, and hopes that's good enough. I believe that's part of the reason client certificates are not poplar; having actual users deal with that is terrible, and the browsers (in practice, Chrome because of its overwhelming market share) isn't incentivized to fix it.by mook
6/14/2026 at 4:04:28 PM
Same on Firefoxby sunaookami
6/14/2026 at 3:46:54 PM
Same on Arcby linsomniac
6/14/2026 at 3:33:21 PM
Same on Zenby jorl17