3 ms·
HTTPS is not secure when we talk about China it is false sense of security! Last case 7days ago: http://www.theregister.co.uk/2015/03/24/google_ssl_cnnic/ http:
by jordanilchev 12y ago
HTTPS is not secure when we talk about China it is false sense of security!
Last case 7days ago:
http://www.theregister.co.uk/2015/03/24/google_ssl_cnnic/ http://www.theregister.co.uk/2015/03/24/google_ssl_cnnic/
- comex 12y agoThat's fairly off topic - I mentioned that HTTPS is somewhat irrelevant here since Baidu is located in China, and anyway a forged certificate could not be used in a mass attack like this one since the issuing CA would come to the attention of browser vendors rather quickly. For the record, hopefully Google's upcoming Certificate Transparency feature in Chrome will help address the general issue, although who knows what kind of adoption it will have in practice.