Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The article is not for the layman but for beginners who are interested in knowing the internals of HTTPS. The explanation is in layman terms. You can find plenty of literature on https online but it's not necessary you would grasp everything in a blink of an eye.


Let's be honest here, the article is to demonstrate that you have some grasp of how https works.

In particular the statement "They confirm the identity of the certificate owner & provide proof that a certificate is valid. " is dangerously misleading for the "layman" as the basic HTTPS certificate issuance does not involve any sort of owner identity confirmation, just that whoever requested the certificate had control of the DNS record for that domain at the time of the request.


Thanks for the feedback, I'll find ways to simplify this & explain it in lucid terms so that readers don't find it difficult to comprehend.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: