Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Outsourcing TLS termination" is intentionally MitMing your users. Not really something to be happy about.


If you're outsourcing your TLS termination to the same people who are running your servers, you've barely made it easier for them to MITM your users. They could easily grab the private key off your server and do it anyway.


That's a big if. I was thinking about services like Cloudflare that terminate SSL close to the user, then tunnel the traffic to your servers. It cuts down on handshake latency and allows for secure distribution of cacheable content easily, but in return you are essentially handing your plaintext over to Cloudflare.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: