Skip to content

Comment on Ask HN: Where should someone buy a SSL certificate?

Comments

If you're worried about certain governments MITMing you, the answer is that it's hopeless to rely on SSL to provide protection.

I don't know a good recommendation. I just wanted to clarify that SSL provides no protection in that particular case.

Makes sense, does that in turn mean that SSL is really a 'hopeless' cause and using self-signed just for the image of 'https' showing in the location bar on a browser enough? Seems like a pointless exercise to me knowing that someone somewhere (government or not) could still access it

Just to clarify, I think using some reliable and trustworthy SSL cert vendor is the way to go. It just won't protect you from the aforementioned parties. Nothing will at this point.

SSL protects you and your users from many other attack vectors, and is important. It wasn't my intention to argue against SSL, just to point out the truth of our modern day situation.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.