Makes sense, does that in turn mean that SSL is really a 'hopeless' cause and using self-signed just for the image of 'https' showing in the location bar on a browser enough? Seems like a pointless exercise to me knowing that someone somewhere (government or not) could still access it
Just to clarify, I think using some reliable and trustworthy SSL cert vendor is the way to go. It just won't protect you from the aforementioned parties. Nothing will at this point.
SSL protects you and your users from many other attack vectors, and is important. It wasn't my intention to argue against SSL, just to point out the truth of our modern day situation.
Comments
Makes sense, does that in turn mean that SSL is really a 'hopeless' cause and using self-signed just for the image of 'https' showing in the location bar on a browser enough? Seems like a pointless exercise to me knowing that someone somewhere (government or not) could still access it
Just to clarify, I think using some reliable and trustworthy SSL cert vendor is the way to go. It just won't protect you from the aforementioned parties. Nothing will at this point.
SSL protects you and your users from many other attack vectors, and is important. It wasn't my intention to argue against SSL, just to point out the truth of our modern day situation.