Hacker News new | past | comments | ask | show | jobs | submit login

I will say safeguards against tampering are getting better for newer browsers. I'm working on a software stack for PirateBox type systems but focused on security, so I get a pretty good glimpse at how a lot of sites handle incorrect certs, since it's an internetless portal and redirects everything to its hosted SSL page. Both gmail and hackernews will refuse to load at all, as they properly support HSTS. Well gmail "cheats" and is hard coded in chrome.



So how does Gmail do it with other browsers?





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: