Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Plaintext is zero security.

Self-signed is a low probability of security.

Signed is a high probability of security.

This continuum makes more sense than the current state of affairs.



If someone forwards plaintext, it's called a proxy.

If someone forwards encrypted content on behalf of my server, it's called man-in-the-middle attack, and they should not be capable of doing it without the huge red flags.


Self-signed is a significant probability of man-in-the-middle attack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: