Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Validating certificates is a good thing and everybody should do it.

That said ... it really only tells you that a certificate is 'sound'. It by no means tells you with 100% confidence that you are talking to the right party.

SSL/TLS is still pretty fragile.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: