> Yesterday, reading this page in plaintext was perfectly fine, but today, add some AES to the mix, and it’s a terrible menace, unfit for even casual viewing.
LetsEncrypt isn't perfect either. You've got to be cognizant of what details you are sharing over the connection, regardless of who signs the certificate.
[https://it.slashdot.org/story/17/03/25/2222246/over-14k-lets...]
> You've got to be cognizant of what details you are sharing over the connection, regardless of who signs the certificate.
So why not cut out the browser errors, for free? Somehow this vaguely feels like Don Quixote straining hard to hold onto the original definition of the term "hacker".
Props to this guy for sticking to his beliefs; I don't mean for this to be interpreted as saying anything should be changed.
- protected from alteration of the data in transit without either end's knowledge
and, IF you have a means to authenticate the owner of the certificate outside of the regular certificate signing process
- protection from impersonation of the other end of the connection
It's just a blog; I'm not submitting anything, but still it's an indicator that something fishy might be going on.