Hacker News new | ask | show | jobs
by nisegami 1251 days ago
The browser shouldn't, the user is the one that needs to make that determination. But right now, the user doesn't even have that choice.
1 comments

You still can have untrustworthy page and user still has to make that determination with TLS or without. If you connect to bad guys server you still will get owned.

Problem is that technically *user should not make that determination* - for casual user TLS is transparent. Which takes burden of technically knowing if traffic was or was not MiTmed out of the question for end user. End users should make less technical decisions because they want to browse websites - not worry about if someone is injecting stuff in their traffic.