Hacker News new | ask | show | jobs
by bawolff 1598 days ago
It is a bit about authentication - it is meant to authenticate you are talking to the owner of the domain (which is different from authenticating the person behind it).

Compare that to pure optimistic encryption which has very different properties than https.

[P.s. If anyone says OV and EV certs... those haven't been very effective so im ignoring them]