Reply to post: Re: Too much trust being put into certificates?

Let's Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers' domains

Orv Silver badge

Re: Too much trust being put into certificates?

I think the problem is encryption without some form of proof of identity only creates an illusion of security; you don't know if the connection is to your intended website, or to a man in the middle who's posing as the legitimate site (and then possibly forwarding the traffic on to it.)

About the only thing that un-authenticated encryption does is slightly deter bulk data collection and storage. It does nothing for any kind of targeted interception.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon