Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps this is a dumb question, but what should the torrent time developers have done differently to have local valid TLS without bundling a private key?


They don't really need valid TLS in the first place for localhost.

At least in firefox Mixed content warnings can be bypassed with custom protocols that declare that they're secure for embedding in secure content.


Generating a unique key for each installation and adding that to the list of root CAs on that computer.


Err... Isn't that what Lenovo did with Superfish?

That sounds like terrible advise.


No. Lenovo used the same certificate for every computer, and pre installed the software without user consent.

Generating a new certificate on the computer it's used on is different.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: