Hacker News new | past | comments | ask | show | jobs | submit login

The point is, sometimes you just don't care about authority, you just care about the encryption.

HTTPS with self-signed certificates is better than moving plaintext over the wire, in the same way PGP is better than moving plaintext over the wire. It doesn't matter that you don't have a "trusted" peer to tell you this PGP signer is who it says it is. As long as you can trust you acquired his key in a secure way (e.g., out-of-band), it's better than the alternative.

Plus, MITM concerns over self-signed certs are moot. This vulnerability exists at the DNS level anyway.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: