3 ms·
Sure, but there's absolutely no way to differentiate between self signed SSL cert and a MITM attack.
by Firehed 14y ago
Sure, but there's absolutely no way to differentiate between self signed SSL cert and a MITM attack.
- nodata 14y agoSure there is: just get the client to remember the cert.
- omh 14y agoHow do you handle things the first time? Perhaps you're always under a MITM attack. And what about when you change the certificate deliberately?
- kalleboo 14y ago> How do you handle things the first time? You compare the fingerprint.
- krisoft 14y agoCompare with what? Honest question, it seems to me self evident that there is nothing to compare to at first time, so maybe I'm mistaken. Would you mind to elaborate?
- nodata 14y agoYou have a fingerprint for your certificate on your server. Google connects to your server, and sees a fingerprint. If they are the same, you don't have a MITM.
- jessaustin 14y agoIs it any better for all affected users to have to 1) figure out what this fingerprint is and enter it and then 2) individually update the fingerprint every time the cert changes, after they figure out that's why they're not getting any email through this particular provider any more? Isn't it easier from Google's perspective to just say "you can't do this" than deal with those complications?
- nodata 14y agoYou're completely missing the point, but to answer your questions: 1. If you're self generating a cert, you know how to do it. 2. It doesn't change very often. This discussion is about Google making a change without warning that has an immediate negative impact on pre-existing users. This discussion is not about new pop3 accounts being added to Gmail.