Skip to content

Comment on 'Trivially easy' to buy SSL certificate for domain you don't ownparent

Comments

I no longer worry about the backbone sniffers - that's like drinking from a firehouse the size of 3 Gorges Dam. You can't surreptitiously consume that much I/O.

I'm much more concerned about small targeted stuff in data centers and colo cages, sniffing just a few backend servers, behind the SSL terminator. Or, you know, just 'select * from creditcardinfo';...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.