Linked by David Adams on Mon 8th Nov 2010 16:49 UTC, submitted by HAL2001
Permalink for comment 449145
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
Features
Linked by Thom Holwerda on 05/21/13 21:38 UTC
Linked by Thom Holwerda on 05/20/13 11:29 UTC
Linked by Thom Holwerda on 05/18/13 21:33 UTC
Linked by David Adams on 05/16/13 4:23 UTC
Linked by Thom Holwerda on 05/11/13 21:41 UTC
Linked by Thom Holwerda on 05/08/13 14:22 UTC
Linked by Thom Holwerda on 05/02/13 15:28 UTC
Linked by Thom Holwerda on 04/29/13 21:06 UTC
Linked by Thom Holwerda on 04/24/13 22:24 UTC
Linked by Thom Holwerda on 04/18/13 11:21 UTC
More Features »
Sponsored Links



Member since:
2006-01-26
I'll agree that the entire concept of SSL certificate/encryption, with CA's and high prices, is indeed a broken system and a scam to some extent - but the "scary errors" browsers display have a valid purpose.
Given how SSL works, and how users expect it to behave, if you can't verify the certificate you're using belongs to the site you are surfing, you can't know that the encryption keys you're sharing with them haven't been tampered with by a middleman. On a public wifi network, this can be a real threat...
In any case - if I encounter a site with an "untrusted" certificate, and I don't figure it matters for that particular site (read: I'm not revealing personal information to the site), then I'll just accept it anyway.
These days, you can get a free Class 1 cert (unrevokable, single domain)... or a cheap Class 2 verification wildcard cert for like $25/year ($50 for two years) from StartCom:
http://www.startssl.com/
All major browsers accept these... so it's hard to complain about it much.
Edited 2010-11-08 22:46 UTC