4 ms·
Fair question. I just checked what exactly the warning message says in IE, and it's actually a pretty fair warning message. Firefox, on the other hand, has a pr
by klync 16y ago
Fair question. I just checked what exactly the warning message says in IE, and it's actually a pretty fair warning message. Firefox, on the other hand, has a pretty scary "This connection is untrusted" page with a pretty confusing explanation of the alleged problem. I don't know if this still happens, but I remember a couple years ago, it was impossible to get IE or Firefox to actually save the cert or remember your preference to bypass the warning, so you would get the warning each time you had a new browser session and tried to connect to the server, no matter what.
The fact is, my real-life identity was never verified as the owner of the domain by a "trusted" third party. However, the encryption key comes from the same server serving the content, so what, really, is not to be trusted? I.e. the cert applies to "domain.com" and is being used on "domain.com". There is no risk of MITM attack, only that "domain.com" is not what you think it is.
- JoachimSchipper 16y agoWell, anyone can supply a key - the problem is that the client could be talking to anyone.
- deleted 16y ago[deleted]
- ominous_prime 16y ago> There is no risk of MITM attack, only that "domain.com" is not what you think it is. That very well could be a MITM attack