4 ms·
The key about self-signed certificates is that while they don't give specific identity assurances, they do give identity assurances across multiple transactions
by ezyang 16y ago
The key about self-signed certificates is that while they don't give specific identity assurances, they do give identity assurances across multiple transactions with the website. That is, the website I talked to yesterday is the same one I'm talking to today.
If I had to implement "automatic" HTTPS, I would probably ask browsers to automatically accept self-signed certificates on the first transaction. Thus, with no user-interaction in the good case, an attacker must manage to MiTM the user on the very first time they access a site, and this is considerably harder to do and less likely to result in interesting information. So I do believe encryption without MiTM protection is a security increase. But there are usability trade-offs and obvious costs for rolling something out like this, and I don't think this particular proposal makes the cut, unfortunately.