4 ms·
Again, what's the risk that a first time visit to a site is going to give you a fake certificate? OTOH SSL has done nothing for preventing phishing, since no C
by jabbany 3y ago
Again, what's the risk that a first time visit to a site is going to give you a fake certificate?
OTOH SSL has done nothing for preventing phishing, since no CAs actually verify anything beyond you owning the domain.
- paulmd 3y agoWell, any time anyone might be loading up a website for the first time in a coffee shop. Also, “remember this cert forever” (cert pinning) has been an ops disaster for a lot of sites that have tried it. So in practice “the first time” might be more like every week or every month. What the risk that a coffee shop will not serve you a malicious cert once a week? Also if they do it and you move back to your home connection… the site is broken there because now it’s returning a different one than was pinned (by the attacker!).
- apostacy 3y agoThere are plenty of ways to improve security but maintain openness. I think a good idea might be to have TOFU and self-signed only as a fallback. If there was no initial mismatch, and then upate cert periodically.