logoalt Hacker News

brian-armstrongyesterday at 8:24 PM2 repliesview on HN

Why would you ever accept a mismatched certificate? Even assuming that you think your ISP has no nefarious plans, are you going to be able to rigorously confirm it's their certificate? At that point you've bypassed all the mechanisms in your browser that do this heavy lifting for you.


Replies

lukanyesterday at 10:08 PM

Erm, where is the danger in a mismatched certificate, if all I want is to get some noncritical information from a blog or something?

embedding-shapeyesterday at 8:29 PM

Why wouldn't you? Your computer is not gonna be hijacked by it, and you want to see what shit your ISP is now up to.

Obviously I don't do my banking like that...