TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Guardian also open-sourced a test SSL cert

33 点作者 boyander超过 11 年前

7 条评论

ctz超过 11 年前
<p><pre><code> Issuer: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl&#x2F;emailAddress=martyn.inglis@guardian.co.uk Subject: C=GB, ST=London, L=London, O=GU, OU=tech, CN=*.int.gnl&#x2F;emailAddress=martyn.inglis@guardian.co.uk </code></pre> This isn&#x27;t the Guardian&#x27;s certificate. It&#x27;s self-signed, for starters.
vxxzy超过 11 年前
This is just a self-signed cert.
评论 #6875070 未加载
评论 #6875506 未加载
quasse超过 11 年前
HTTPS does not seem to be properly configured on their servers anyway, I get an &quot;You attempted to reach www.theguardian.com, but instead you actually reached a server identifying itself as *.a.ssl.fastly.net.&quot; error when trying to connect over HTTPS.<p>That&#x27;s interesting because they do have content protected by a sign in system. Are they just not using HTTPS for that? I kind of expected more from the Guardian.
评论 #6875153 未加载
clone1018超过 11 年前
Wouldn&#x27;t this allow someone to do a full man in the middle attack with a compromised server&#x2F;dns server?
评论 #6875069 未加载
anilshanbhag超过 11 年前
So now anyone snooping on visitors to Guardian&#x27;s site can decrypt the communication. Don&#x27;t see why anyone would waste time on this given that there is no &#x27;money&#x27; involved.
boyander超过 11 年前
Yes, just checked now.
samuel1604超过 11 年前
it&#x27;s not the real one it&#x27;s a test SSL cert