logoalt Hacker News

mrsssnaketoday at 7:34 AM0 repliesview on HN

Why when connecting to a TLS website service that does not have a CA signed certificate, I am welcomed with "Secure connection failed, browser not trusting the ceritifate. Do you want to continue?", without showing me the actual certificate fingerprint?

On desktops browser displaying the fingerprint/hash requires clicks, on mobile is not implemented and on native apps practically not existing.

The keys should be shown, so they could be verified manually in person or via other channel. Just like the SSH do. Someone say people would just click "accept" without a thought, but the button is already here, just no information what actually is accepted.