Hacker News new | ask | show | jobs
by st3fan 5080 days ago
Validating certificates is a good thing and everybody should do it.

That said ... it really only tells you that a certificate is 'sound'. It by no means tells you with 100% confidence that you are talking to the right party.

SSL/TLS is still pretty fragile.