Hacker News new | ask | show | jobs
by profmonocle 2657 days ago
Unless a site is hosted on the site owner's physical hardware, some third party is being trusted this way. A shared hosting provider could dump the server traffic, a VM provider could extract TLS session keys from the guest's memory.