Hacker News new | ask | show | jobs
by SkyMarshal 3665 days ago
That only secures the transport, not necessarily the source. Especially without a checksum or digital sig to verify the source, it's a little weird of an oversight for a company like 21.
2 comments

How would that checksum or digital signature be distributed?

HTTPS checks for authenticity of source (it uses digital signatures). Now, I guess there could be a rogue CA which creates another certificate for 21.co, but excluding that it's fine.

woosh