Re: Draft finding - "Transitioning the Web to HTTPS"

On Mon, Jan 19, 2015 at 12:51 PM, Paul Libbrecht <paul@hoplahup.net> wrote:
> Please make browsers reasonably acting when contacting web-site that
> presents self-signed, expired, and other such certificates are used.
> The crypto still happens, it's just less verified.

How do you distinguish that happening from a man-in-the-middle attack
without every site that uses TLS also adopting key pinning (and the
administrative nightmares that gives)?

Anything but proper CA certificates is a major attack vector and if
anything we should move towards making it impossible to connect to
such sites.


-- 
https://annevankesteren.nl/

Received on Monday, 19 January 2015 11:59:47 UTC