3 ms·
If it's SSH or HTTPS you aren't - the SSH client will check the fingerprint and abort on unknown, and the HTTPS client should check the certificate and verify t
by nirimda 4y ago
If it's SSH or HTTPS you aren't - the SSH client will check the fingerprint and abort on unknown, and the HTTPS client should check the certificate and verify that it was issued when a trusted client could access the same server via the same name. But if you have access to bind to a port, you can trick the trusted HTTP client as much as the end-user client. Maybe SSH is a slightly stronger guarantee here - if port binding permissions are holding out to the extent we haven't disabled them, then file read permissions are probably holding out too.
- foota 4y agoYeah I would argue if you want security you need to be using something like mutual tls, or a framework/system/etc., that provides the same. That's from the perspective of the developer though, from an end user's perspective I guess you just hope your application is, or that it's something where it doesn't matter.