Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Almost no one comprehends https either. Yet it seems to work well enough to protect people.

That's because it's entirely up to site operators (and browser/os vendors to add trusted registries) and not to the user.

If it was to the end user to install something and manage certs for https, it wouldn't work at all...



Article author seems to be suggesting that Gmail et al. manage the key signing though, so still the same as https in that regard.


Private use? yeah, not so great with the current state of software for it. Company environments: that's what sysadmins are for. You see the occasional company where everything is signed with S/MIME.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: