3 ms·
To not sign malicious agents so they can act like they're the website you're actually trying connect to. There's a worryingly large amount of CA in Firefox or o
by mburee 5y ago
To not sign malicious agents so they can act like they're the website you're actually trying connect to. There's a worryingly large amount of CA in Firefox or other browsers, many of the quite shady or government-owned
- remram 5y agoThis can happen regardless of whether you set up a certificate yourself. If you're using plain HTTP, someone can MITM in HTTP, and a rogue authority can issue a certificate to someone who isn't you. This is not an argument against you using HTTPS at all.
- enriquto 5y agoSo, you are admitting that HTTP and HTTPS are both equally insecure (they can be blocked or falsely approved by malicious authorities/service providers). At least, plain HTTP seems harder to censor: you do not need anybody's permission to transfer HTTP. Self-signed HTTPS would be even better, but it seems to be frowned-upon by browsers these days.
- remram 5y ago> you are admitting that HTTP and HTTPS are both equally insecure Absolutely not. I am pointing out that even within your (incorrect) assumption, you using HTTPS does not hurt your security at all. That you take it to mean "HTTPS is insecure" is your own assumption, that you take it to mean "equally as insecure as HTTP" is something you made up. A parallel: A lot of companies make seatbelts, you're not sure you can trust all of them. Even though they would be caught by quality testing and instantly go under, it is possible that one of them would build them with cheap materials that wouldn't offer much protection. Therefore seatbelts are not completely safe. Therefore wearing a seatbelt is equally as safe as not wearing one.