Hacker News new | ask | show | jobs
by rsanders 4748 days ago
The (theoretical) security value of proving a secure connection to uglyrandomletters.cloudfront.net is significantly less than the value of proving a secure connection to TheSiteYouTrust.com.

When a group of U.S. ISPs first started working on anti-phishing solutions, we realized that the problem with SSL is that apparently nobody told users they needed to check anything but the golden lock icon to verify security. "Oh, look, I have a secure connection to bankofamerica.b1llingprovider.com, seems legit".