Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends who your perceived thread is really. If you're trying to avoid a government MITM'ing you, sure, in a sense that's more secure.

The chief issue in all this is the huge number of trusted CA that are the default in most operating systems. My install of OSX for example has 181 default certificate authorities, and any one of them could be compromised. I'd be willing to bet that a sizeable portion are under nefarious control.

Just to make a point I picked a random CA and tried to look up some information about it. Couldn't reach their site the first time, as they are lacking an A record on their domain root. I've no idea why they would be trusted, as they look sketchy as all hell — http://www.valicert.com/






Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: