|
|
|
|
|
by LoSboccacc
3571 days ago
|
|
because the whole thing lives off trust. if any certificate could be self signed for getting the browser trust, all MITM attack would go unnoticed unless the browser is pinning the hash of specific domains. that's why it's so important to blacklist fast certificate authority that do no domain ownership validation; it's a frail system, but it's the best we got for now. |
|
All of your concerns require an assumption that the browser uses unauthenticated encryption the same as PKI authenticated. Please stop conflating encryption with authentication; they solve different problems. This attitude that a partial solutions should be actively discouraged is why the internet is still uses plaintext which should have been dropped years ago.