Hacker News new | ask | show | jobs
by StavrosK 3104 days ago
Why not? How hard is it to get a cert for a domain that looks like paypal-businesscenter.com?
1 comments

Moreover, the browser could remember the expected shared secret based on its and the server's RSA exchange.