←back to thread

314 points Bogdanp | 2 comments | | HN request time: 0.523s | source
Show context
msgodel ◴[] No.44380911[source]
This is incredibly dumb. The three way handshake and initial key exchange is your certificate.
replies(2): >>44381814 #>>44382226 #
Dylan16807 ◴[] No.44382226[source]
And this protects you from a hostile network how?
replies(1): >>44382560 #
msgodel ◴[] No.44382560[source]
How does the certificate? If you already have to do the TLS handshake it doesn't change anything.
replies(1): >>44383605 #
1. Dylan16807 ◴[] No.44383605[source]
A verified certificate lets you know you didn't handshake with an attacker in the middle.
replies(1): >>44387620 #
2. msgodel ◴[] No.44387620[source]
Let me rephrase that: How is the CA supposed to know they didn't handshake with an attacker? All they have is the IP, there's no identity to check like with DNS.