3 ms·
Consider the discussion taking place in other comments - SSL has never guaranteed a conversation between client and a server at the "end". The concept of one se
by RadioactiveMan 12y ago
Consider the discussion taking place in other comments - SSL has never guaranteed a conversation between client and a server at the "end". The concept of one server at the end of your connection is wrong. Often, you'll be connected to a load balancer that terminates SSL and communicates with other servers over plain text. Or, you might reach an HTTP server that communicates with other services ( perhaps a database ) and you have no guarantee that those connections are over SSL or take place on internal networks ( as if internal would make it more secure ). Besides SSL itself and the serving of your particular request, what else is being done with the information you've sent? Perhaps they're storing data or sharing it in ways you would not approve of. Trusting the services you connect to is the real tough problem and it has little to do with SSL.