|
|
|
|
|
by LeifCarrotson
86 days ago
|
|
It's true that the expiration doesn't mean the encryption no longer works, but if the user is under a MITM attack and is presented by their browser with a warning that the certificate is invalid, then the encryption will still work but the encrypted communication will be happening with the wrong party. I don't trust the average user to inspect the certificate and understand the reason for the browser's rejection. |
|