[Info-vax] Certificates
Gary Sparkes
mokuba at gmail.com
Mon Sep 11 17:11:04 EDT 2023
On Monday, September 11, 2023 at 4:50:57 PM UTC-4, gah4 wrote:
> On Monday, September 11, 2023 at 1:12:17 PM UTC-7, Gary Sparkes wrote:
>
> (snip)
> > All internet SSL certificates are worth is identifying the remote host
> > (assuming no private key compromise) and encrypting traffic
> > between the two. They imply or do nothing else.
> They are needed to avoid "man in the middle" attacks.
>
That's precisely the point I was trying to make - that's all they're good for.
Identify the machine - "Is this the host I want to connect to?"
Encrypt the traffic between you and the machine -
"I know who i'm talking to now, and no one can read this and we
can detect if it's been modified(invalid data)/intercepted
(certificate changes)"
More information about the Info-vax
mailing list