Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They’re not useless. They stop passive adversaries, like the Australian government. They just don’t stop active adversaries.

Browser security warnings imply https > http > self signed https. The correct order of should be https > self signed https > http.



We're getting there, HTTP is going to be marked as insecure in the future as well. It's just the massive amount of HTTP sites that couldn't get marked as insecure before, due to the then resulting warning fatigue in users.


Allowing untrusted certificates for https, and showing just a warning for them, would make it impossible for websites to ensure that their traffic is not intercepted


Interesting point. BTW I love your blog and your work on ShareJS :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: