|
|
|
|
|
by wallunit
3571 days ago
|
|
I never got, in the first place, why browsers show a big fat warning when accessing a properly encrypted website where the certificate can just not be verified, while a completely unencrypted website on the other hand looks just legit in the address bar. |
|
If a site doesn't have a certificate , there's no identity verification at all and whether or not to trust the site is left up to the user.
If it does have a certificate, and the certificate doesn't appear to be validated by a CA for the domain or organization, or whatever, then there's a risk of misplaced trust. Anyone can issue a certificate for any domain, but they're only "trustworthy" if they've been signed by a CA.