Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If your browser will accept the certificate that the server presents, anyone can pretend to be anyone and your browser will accept it.

Yes but at least the data is protected from eavesdroppers that don't control any hardware in the line of the connection, which is better than nothing.



Most browsers let you accept a particular certificate for a particular site already, just like SSH, so you can already have this if you want. Part of the reason it works so well for SSH, though, is "security through unpopularity": you don't have large numbers of naïve users doing online banking at Starbucks over SSH. If SSH became more popular, you'd need to verify the fingerprint, and then you're back to square one ("If I have a secure channel with which to verify the identity of the SSH key, why not just use this same channel to establish the secure session?").


Except that if I want to accept a self signed certificate I have to click 6 times through scary warning screens.

And that is a good thing because that cert is for both encryption and identity.

If it were JUST for encryption, there'd be no issue just auto accepting that certificate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: