Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most anyone who is in a position to reliably MITM an HTTP site would also be in a position to install a certificate source (either as part of a “install this to access the web” program or similar).

It’s a necessary level of defense but it is NOT sufficient- especially if you never check certificates.



I highly recommend you do a search for Firesheep - the tool that really started the push for HTTPS everywhere. You're right that a malicious network operator would be in a position to request users install root certs, but the problems with plaintext HTTP are deeper than just that.


Not really. In my experience it's always been an ISP that modified the HTTP in transit (to add their own advertising and analytics JavaScript inline), and the ISP didn't have the ability to install a certificate source.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: