Why it's there in the first place, then?
Why it's there in the first place, then?
Posted Jun 18, 2011 7:21 UTC (Sat) by speedster1 (guest, #8143)In reply to: Why it's there in the first place, then? by Lennie
Parent article: WebOS: the other Linux-based mobile platform
This does sound like a useful service, but an experienced admin may still choose to use self-signed for non-public servers (e.g. the imap server) because they trust their own security measures better than those of some third party CA. Or, even if their security measures are not actually better, their server is much less interesting to attackers who love to get control of a widely accepted CA... so the risk of compromise is still lower.
It was not long ago that an official certificate authority was compromised and the attackers generated untrustworthy certificates.
