Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is often cited as the reason (but there are plenty more):

https://en.wikipedia.org/wiki/Man-in-the-middle_attack

If the CA's are doing their jobs...then FirstBank.com can get a cert for their web site. But the gang who rooted a bunch of home routers (or hacked a WiFi setup, or whatever) can't.

If not...then yeah, that's the problem.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: