Hacker News new | ask | show | jobs
by streetfighter64 1 day ago
If there's a zero-day in TLS there would be a huge amount of problems that a VPN wouldn't protect you against. Even if you're using a VPN (or just a trusted ISP from your home), as soon as your data leaves their hands it would be vulnerable.

Like, suppose I want to send a physical letter to my bank. I can either ensure it can't be opened (using TLS), or I can get a trusted mailman to bring it to the mail central (using a VPN or trused ISP), but only one of those measures are going to protect me against a malicious mailman carrying it from the mail central to the bank.

1 comments

I’d expect the mail carrier who goes from the mail center to the bank to be slightly more trustworthy than the one who visits me off in the middle of nowhere. Or at least, if that carrier is untrustworthy, it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff.
> it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff

Because banks famously love spending time and money on IT security... Anyway, if TLS was broken, that would be a big problem for everybody.

Using a VPN to protect against a zero-day in TLS, is sort of like hoarding gold to prepare for a collapse of society, in that it's a very unlikely scenario, and if it actually were to happen you'd have a bunch of other problems that aren't solved by gold / a VPN.