Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not even that complicated.

The problem with not having a valid certificate is this: if both sides can't tie every packet in the SSL handshake back to Verisign or Thawte's pubkey, attackers can inject their own handshake passwords and set the session key.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: