Hacker News new | past | comments | ask | show | jobs | submit login

>They issued their own root certificate and they use it to sign all users certificates.

In our case I think we even have our own CA trusted by the browsers so there's no apparent reason for the self-signing.

>If you teach users to ignore HTTPS errors, then MITM attack becomes easier because user don't see anything suspicious.

That's precisely the point I made to the "technical" person and it was ignored...




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: