3 ms·
> They're not down and this definitely doesn't compromise the encryption that protects any login credentials That is precisely what it does. Serving an invalid
by willstrafach 8y ago
> They're not down and this definitely doesn't compromise the encryption that protects any login credentials
That is precisely what it does. Serving an invalid certificate and requiring user click-through allows for a man in the middle attacker to inject their own certificate without further error and will therefore be able to intercept login credentials.