Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reminds me of Cloudflare's "Flexible SSL", where backend connections aren't encrypted at all.


As someone who has used Flexible SSL, it's perfectly reasonable for some threat models. In our case, credit cards and passwords were both managed by external services and the actual data we stored was not sensitive. We really just needed to prevent account hijacking in cafes via Firesheep.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: