Hacker News new | past | comments | ask | show | jobs | submit login

That's definitely true. Basic SSL hardly amounts to verification beyond the ability to find a valid credit card, yet browsers will accept the generated certs without a question.

To the OP's point, I'm perfectly happy to generate self signed certs, but I find that browsers make using them more inconvenient than necessary. That's the part that seems a bit conspiratorial to me. It wouldn't be hard at all to pop up a very clearly worded message "this is a self-signed certificate with fingerprint xxx, would you like to accept it [once] [every time]". Safari and Firefox aren't too far far from this, but I find chrome and IE to be obtuse at best.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: