Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"""Anytime you use a self-signed certificate ANYONE who controls the network hardware between you and the second party can eavesdrop and even tamper with the communication stream. Neither you nor the second party has any way of knowing what's going on. That's why we NEED a warning every time we encounter a self-signed certificate."""

I believe that you misunderstand the technology.



I'm by no means an expert on crypto but I think I understand the fundamentals. If something I said is incorrect please point it out specifically. See [1] for a more complete explanation of my point.

[1] http://en.wikipedia.org/wiki/MITM




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: