Re: HTTPS vs. HTTP ?
| From: | Miguel Cruz | Date: | Sat, 06 Jul 2002 07:57:42 +0000 |
| Subject: | Re: HTTPS vs. HTTP ? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105840@lists.php.net to get a copy of this message | ||
On Fri, 5 Jul 2002, Richard Lynch wrote:
> But unless you paid the $200 to get it from a CA, surfers will see a nasty
> (and totally inaccurate/misleading) warning about how insecure it is.
It is easy to launch a man-the-middle attack against a session being
initiated between a client and a server with a self-signed certificate.
You just send the client a self-signed certificate of your own, and it
can't tell it apart from the real one - same error message shows up.
miguel