2 ms·
> I assume many people have used it with no issue This is also a dangerous assumption. If 95% of HN is outside of China, they'll have no issue with the website
by Cpoll 4y ago
> I assume many people have used it with no issue
This is also a dangerous assumption. If 95% of HN is outside of China, they'll have no issue with the website, but that validation is meaningless for the 5% behind the Great Firewall (percentages invented).
> Well if we think the site is a honeypot
That's not the logical assumption to make. A honeypot would have a valid certificate.
A broken certificate simply means either
a) the website you are visiting is misconfigured, or
b) a third party has intercepted your (possibly you, *personally*, and no-one else) communication with that website. You are not communicating with the website, you are communicating with the 3rd party. This might mean something as stupid as your ISP injecting ads into websites (a thing that happened before https was so prevalent), or it could mean a government-level actor with a more nefarious agenda.