Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm strongly in favor of encrypting the channel even without signed certificates. A self-signing certificate doesn't authenticate the session but it can be used to later verify that the other end hasn't changed.

Because it's comforting to know that you handed over your private information to a man-in-the-middle and nobody else.



And that is somehow worse than letting this 'man' just read the same information any time in Wireshark without ever getting to the middle?

Note that with self-signed certificates the man can only attack in the middle on the very first connection. After that the other end will be known (not authenticated, but known!) and the browser can guard that.

Currently, I trust my home DSL connection to not have eavesdroppers everytime when I authenticate to some web service over HTTP. Doing the initial connection once using the same network wouldn't be any worse but it would be much better when using any public wifi when I don't know exactly who is providing the service or who is intercepting the wireless connections.


Errr... Are we advocating HTTPS everywhere? Or just when it's time to transfer private information?

When I want to read an essay on some random website, to I need to now that the website owner is who they say that they are? Isn't self-signed HTTPS better than just plain old HTTP? Or is it better that we only use HTTPS for a select few sites that aren't self-signed and HTTP everywhere else?


If you're not transferring private information, why does it matter if it's encrypted? Either you care if someone can eavesdrop or you don't.


The whole online presence might be something that some regard as private since reading a given URL might be as private as a forum password or card info.

But 'either you care or you don't' seems too inflexible to me.

For example, I might care that my bank has a certificate signed by a CA.

But for some usergroup's online forum, a self-signed certificate is enough. Sure, we might get some MITM but the barrier to this is so high and the relative importance of the online forum so low, it seems an adequate trade-off. I'd say there's a higher chance of the server hard drive failing than to see an actual MITM attack on a given niche server.

But overall, as I've said in another message here, I see this whole centralized design as flawed and much too expensive. Certificate info should be a DNS attribute.


If you only use encryption when you 'have something to hide,' then use of encryption is enough to incriminate you.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: