Hacker News new | ask | show | jobs
by yarg 597 days ago
> Because Chrome even explicitly states that traffic to a site with an expired certificate is unencrypted.

If that's the case, then Google's condescension is doing a disservice to its users.

1 comments

(Tested with Chromium, at https://expired.badssl.com) It says "Not Secure" on the left side of the address bar. It says "Privacy error" as the tab title. And then the body of the page:

<bold>Your connection is not private</bold> Attackers might be trying to steal your information from expired.badssl.com (for example, passwords, messages, or credit cards). Learn more about this warning net::ERR_CERT_DATE_INVALID