Hacker News new | past | comments | ask | show | jobs | submit login

> Doesn't really matter where its hosted when most North American connections go through New York

Actually, it does matter. Https is end-to-end encryption. An eavesdropper in New York would have to crack SSL in order to see anything meaningful beyond the fact that you exchanged some data with hulbee.com .




I would bet that the NSA has access to most root certificates... specially when they've had access to hard drive firmware for the last few years...

http://www.wired.com/2015/02/nsa-firmware-hacking/


If you used a CA certificate to sign a new SSL cert for any popular domain, it'd be detected by certificate fingerprinting and you'd burn the CA. Not worth it over public networks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: