4 ms·
I fail to understand how gmail accepting to fetch email from an account without any sort of encryption, but refusing to fetch email from my CS department which
by St-Clock 14y ago
I fail to understand how gmail accepting to fetch email from an account without any sort of encryption, but refusing to fetch email from my CS department which has a self-signed certificate can benefit me or make me more secure...
- martin_k 14y agoDisallowing self-signed certificates doesn't improve security of unencrypted connections, but it increases security of all connections using SSL/TLS. It doesn't make you more secure (you don't have strong authenticity in any of those cases), but it certainly makes me more secure. When Gmail fetches email from my provider, which has a certificate signed by a trusted CA, it would have previously accepted any self-signed certificate from an active MITM.
- St-Clock 14y agoThanks for clarifying. I understand the decision better now. How about an option (disabled by default) that allows self-signed certificate per fetched account, e.g., in the "edit info" dialog? I guess everybody would be happy with this one right?