6 ms·
> don't require messing around with HTTPS certificates. Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously
by echoangle 16d ago
> don't require messing around with HTTPS certificates.
Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously checks the host key on first connection.
- account42 15d agoMost reasonable countries have the same defense against that as you get against someone stabbing you. I don't see many security professionals insisting that you have to walk around in plate mail for some reason.
- slowin 16d agoYou get notified if the server key changes though. I don't think it's fair to say there's no defense against MITM.
- dolmen 15d agoThat doesn't protect against MITM happening on the first connect.