Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You lose 50% of the benefit of HTTPS then. It is 1/2 about encryption and 1/2 about interception/impersonation/MitM protection.

The only way to do a self signed cert while maintaining all of the benefits is to have the client install your root CA into their CA store. However for the user to do so they have to fully trust you and your security (since for all they know you could generate fake certificates for Microsoft, Google, Amazon, etc that would show up as legit for them (certificate pinning aside)).

I really REALLY dislike the current HTTPs/SSL/TLS system, the fact that money and hassle is a literal cost to security is a huge problem. However self-signed certificates aren't remotely a solution.



no, they arent a solution, but they arent a problem either. think ssh/know_hosts - file.

convergence might have been an interesting approach, but i did not heard much of it lately http://convergence.io/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: