Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> don't require messing around with HTTPS certificates.

Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously checks the host key on first connection.

 help



Most reasonable countries have the same defense against that as you get against someone stabbing you. I don't see many security professionals insisting that you have to walk around in plate mail for some reason.

You get notified if the server key changes though. I don't think it's fair to say there's no defense against MITM.

That doesn't protect against MITM happening on the first connect.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: