Live data from Hacker News

Thepiratebay.se SSL certificate expired on 2/2/13 3:52 AM

thepiratebay.se

1–10 of 21 posts

Re: Thepiratebay.se SSL certificate expired on 2/2/13 3:52 AM

#5
What does this actually mean? To me, the obvious part is that people in coffee shops could be targeted. Is the most dangerous part about it to do with ISPs? They already could know what pages you visit TPB anyway, couldn't they? In Fiddler today all I seemed to see were handshakes to a secure site I host, but I couldn't see what pages or assets were requested. Do ISPs have the same problem?

Re: Thepiratebay.se SSL certificate expired on 2/2/13 3:52 AM

#6

What does this actually mean? To me, the obvious part is that people in coffee shops could be targeted. Is the most dangerous part about it to do with ISPs? They already could know what pages you visit TPB anyway, couldn't they? In Fiddler today all I seemed to see were handshakes to a secure site I host, but I couldn't see what pages or assets were requested. Do ISPs have the same problem?

exactly my question, since I'm not the security expert either. I'm wondering, why there was no announcement about it, if it did happen few days ago (or today)

Could it be that they have something local now ? Not many SSL providers would side with them is evident.

Re: Thepiratebay.se SSL certificate expired on 2/2/13 3:52 AM

#8

What does this actually mean? To me, the obvious part is that people in coffee shops could be targeted. Is the most dangerous part about it to do with ISPs? They already could know what pages you visit TPB anyway, couldn't they? In Fiddler today all I seemed to see were handshakes to a secure site I host, but I couldn't see what pages or assets were requested. Do ISPs have the same problem?

Unless ISPs can magically decrypt HTTP requests, all they can see are sending & receiving IP and port. Without SSL, ISPs can view everything (unless tunneling or something similar to add encryption to an unencrypted protocol).
Post reply on HN