Hacker News new | past | comments | ask | show | jobs | submit login

How would the attacker do anything useful with a SSL connection attempt? They can either send the real certificate, and then not be able to decrypt the data, or send a self-signed cert which the OS/browser wouldn't trust?

Are you thinking of some downgrade attack vector?

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
