Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, that is not exactly true. If you use SSL, there will be authentication. Eve-in-the-middle cannot craft certificates or feed the browser with her fake certificates. No 3rd party HTML/Javascript/whatever code can change this. So there is a higher level of security with SSL.


Definitely true but this scenario worries me:

1. Get a signed cert from a recognized CA (fraudulently - not impossible).

2. Hijack the DNS (e.g., get their GoDaddy password, or point them to a DNS server you control)>.

3. The user is directed to the fake server with the fraudulently obtained cert, and does not receive a warning.


Absolutely, authentication is not bullet-proof. That's why certificate authorities have to invalidate certificates from time-to-time.


True, and of course they can only revoke the ones they know are fake. And the browser/client has to respect the revocation list.


that's what I'm trying to say, too. I meant that you're not safe even with DH and have to use SSL




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: