|
|
|
|
|
by sneak
3923 days ago
|
|
First, they have to care. Second, they'd have to MITM your network connection. The chance of a single party being able to do both of those is very, very low. Sure, it's not best practices. Is it better than what R&D teams are doing now? (Unvalidated self-signed certs, or no encryption at all.) Absolutely. People complaining about this are like people who complain about invalid cert warnings not being strong enough (or too easy to disable) while half the world still browses with http with no warnings. It's a significant improvement over the status quo. |
|