Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Come on, it's not literally the same. It at least requires an active attacker to read your data, whereas HTTP can be read passively.


You're right. It's not literally the same. However, it is effectively identical.

It is absolutely trivial for even a 5 year old to click a button and perform a downgrade attack on this type of an https:// connection. That is why accepting any self-signed certificates should be treated identically to http:// connections.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: