Hacker News new | ask | show | jobs
by castorio 4373 days ago
using the CA-model in its current way doesnt protect you from MITM either. diginotar anyone? http://en.wikipedia.org/wiki/DigiNotar
1 comments

It absolutely does protect you from MitM. Does it offer full proof protection? No. But it adds a barrier between you and being trivially hit with a MitM.

To use an analogy: One could make the statement that a kevlar vest doesn't protect you from bullets, then cite an example when a military grade round went through one and killed a cop. However this statement would be equally misleading to yours, as we all know a kevlar vest is better than nothing and that it will stop a typical street bullet (e.g. handgun round).