4 ms·
It's FUD to say encryption doesn't matter without authentication - unencrypted traffic is eavesdroppable by default and exposes you much more broadly than just
by beefsack 8y ago
It's FUD to say encryption doesn't matter without authentication - unencrypted traffic is eavesdroppable by default and exposes you much more broadly than just being exposed to one potential bad actor.
Of course using authentication is vastly superior, but lacking it doesn't render encryption useless.
- azernik 8y agoWithout authentication, a man in the middle is indistinguishable from your intended target, so you are exposed to anyone on the network path.
- laumars 8y agoLets be clear, we're not talking about self signed certs here. An attacker would still need to prove they have ownership of the domain to get a non-EV CA-signed certificate which makes a MITM attack highly challenging to the point of being down right impractical to accomplish successfully. Its not simply not a large enough threat level* to worry about since it would require either DNS spoofing (in which case why bother with a MITM anyway since you now have ownership of the traffic you can just steal people's cookies and get log in directly), or access to the domain owners email (in which case gaining access to their infrastructure becomes significantly easier depending on where it is hosted) or attacking the clients PC to install your own CA certificate (in which case yiu might as well just install a RAT or keylogger and capture inputs for all websites and thus save yourself the trouble of MITMing only one specific single domain). * I mean if your business is online banking then it's a little different. But for 99.9% websites out there having EV isnt necessary.
- KMag 8y agoAnyone in the network path and willing to expend the computational power to decrypt and re-encrypt your traffic. Unauthenticated encryption still dramatically increases the cost of mass surveillance.
- snowwrestler 8y agoBrowser makers must not agree with you, because self-signed certificates get huge warnings, but HTTP connections get at most a little "Not Secure" notice in the address bar.