Hacker News new | ask | show | jobs
by rbritton 3821 days ago
Could you not also argue that ongoing use of HTTPS after authenticating yourself with the server is to ensure the response is coming from who you intend (i.e., the server authenticating itself to you)?
2 comments

IANAL, but if you assume law matches cryptographic reality: there's such a thing as the NULL cipher, which most SSL stacks don't support (at least by default) because it's a big footgun. It will let you have traffic that's authenticated but not encrypted.
What would you rather do, argue with the US government or get an ERN and focus on your business? I know my answer ;)