logoalt Hacker News

embedding-shapeyesterday at 6:35 PM2 repliesview on HN

> No notification

What ISP? I'm using Vodafone and if I accept the insecure connection (because of mismatched certificate), I get served the notification. You don't get that?


Replies

brian-armstrongyesterday at 8:24 PM

Why would you ever accept a mismatched certificate? Even assuming that you think your ISP has no nefarious plans, are you going to be able to rigorously confirm it's their certificate? At that point you've bypassed all the mechanisms in your browser that do this heavy lifting for you.

show 2 replies
tomnipotentyesterday at 6:50 PM

Presumes you're using the ISP's DNS and not custom servers or DoH.

show 1 reply