Skip to content

Comment on The Case of the Modified Binariesparent

Comments

not always. as we've learned from the NSA disclosures, there are many layers of indirection.

Would you say its better than plain HTTP?

Or is the false sense of true security a bigger detriment?

Or is the false sense of true security a bigger detriment?

That's a really tough call.

Cloudflare makes no security guarantees. They don't even commit to keeping your public key secure when you give it to them. That's a bad sign. One wonders how they fund their free MITM service.

i think it really depends on your threat model

This is important; there are cases of "just plain insecure" but other than that, it's very nuanced.

How about you randomly generate and write all your passwords down on a piece of paper in your wallet? For many threat models, that's far more secure than even using a password manager. For other threat models it's far less secure than using a password manager. Other than things that are just flat-out broken "more-secure" and "less-secure" don't exist without qualification.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.