this post was submitted on 16 Dec 2024
362 points (97.9% liked)
Technology
60301 readers
3210 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Okay, but (if the big ones didn't enforce it) a home made cert would also stop a man in the middle attack.
And if I figure it's compromised, I just deal with it through my hoster or on my home-lab server.
I just don't see why it should be a "trusted" entity in there at all. I know today it is how it works but I feel we could and should do away with it (in magic wonderland I guess :-)
It would not, because the "man in the middle" would simply provide their own, also self-signed certificate, to the client and the client would have no way of verifying that that certificate is not to be trusted. The client is unable to distinguish between your self-signed cert and the attacker's. That's why the CA is needed, to verify that the certificate is actually issued by whoever you think it is.
This is why browsers do not trust self-signed certificates. They can't verify who that "self" is. Doing away with it is a massive security vulnerability.
Thanks for the explanation it does make sense.