Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
gthank
on Oct 12, 2009
|
parent
|
context
|
favorite
| on:
SSL Still Mostly Misunderstood
Then generate your own certs and self-sign.
jcl
on Oct 12, 2009
|
next
[–]
As I understand it, self-signed certs leave you open to man-in-the-middle attacks.
http://news.ycombinator.com/item?id=277284
axod
on Oct 12, 2009
|
prev
[–]
Still pops up warnings for users in browsers.
chowmeined
on Oct 13, 2009
|
parent
[–]
As they should. Since there is no way to verify the remote server then the connection is vulnerable to man-in-the-middle attacks. In that situation an attacker can simply pretend to be the server and decrypt your traffic.
Consider applying for YC's Winter 2027 batch!
Applications
are open till November 2.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: