Re: Draft finding - "Transitioning the Web to HTTPS"

On Sat, Dec 13, 2014 at 4:47 AM, Marc Fawzi <marc.fawzi@gmail.com> wrote:
> If my browser can detect the sever's capability, gets it's public key ...

Without authentication, which is what the CA system provides, this is insecure.


-- 
https://annevankesteren.nl/

Received on Saturday, 13 December 2014 10:44:57 UTC