Hacker News new | ask | show | jobs
by noerps 4756 days ago
With SSL, both parties negotiate synchronous encryption (like in AES) and key exchange (like in RSA) for that, the trust is established with signed certificates obtained from a 3rd party. Which is/was fine on paper and concept, the implementation sucks and we don't have alternatives to that.