2 ms·
> don't require messing around with HTTPS certificates. Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously
by echoangle 25d ago
> don't require messing around with HTTPS certificates.
Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously checks the host key on first connection.
- slowin 25d agoYou get notified if the server key changes though. I don't think it's fair to say there's no defense against MITM.
- dolmen 24d agoThat doesn't protect against MITM happening on the first connect.
- account42 24d agoMost reasonable countries have the same defense against that as you get against someone stabbing you. I don't see many security professionals insisting that you have to walk around in plate mail for some reason.