3 ms·
It's not inherent to SSL/TLS, it's a general issue. If you can't verify that the encryption key you're using actually belongs to the person you think it does, y
by kronusaturn 16y ago
It's not inherent to SSL/TLS, it's a general issue. If you can't verify that the encryption key you're using actually belongs to the person you think it does, you're only protected against passive eavesdropping. Which buys you only weak protection against government mass surveillance, and none at all against someone doing something like DNS spoofing.
On the other hand, the whole top-down certificate authority model is pretty weak anyway, especially since browsers don't provide any warning when a certificate for a site you've visited before has changed before its expiration date.