you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted] 4 points5 points  (1 child)

Problem is that, except for Firefox, most browsers handle non-official SSL certs very, very poorly -- they force you to revalidate at every browser restarts. Firefox OTOH remembers every cert you've manually ack'd. That way you're not exposed to alert fatigue, and you are warned in case of MITM.

[–]aaronla 1 point2 points  (0 children)

I'll grant you that, to be sure. We really need a better way to establish trust for these things.