Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SSL documentation in most major projects still needs a lot of polishing.

I also think there needs to be a push to separate the encryption and remote server verification parts of SSL/TLS. I'd love to encrypt all communication with the sites I run, but am completely uninterested in coughing up cash for an SSL cert.



Then generate your own certs and self-sign.


As I understand it, self-signed certs leave you open to man-in-the-middle attacks.

http://news.ycombinator.com/item?id=277284


Still pops up warnings for users in browsers.


As they should. Since there is no way to verify the remote server then the connection is vulnerable to man-in-the-middle attacks. In that situation an attacker can simply pretend to be the server and decrypt your traffic.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: