且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

没有有效的SSL证书,HTTPS连接是否安全?

更新时间:2023-11-25 16:07:46

即使SSL证书无效,连接也会被加密(已过期,蛇油,不受信任的CA等)。 SSL证书验证只是确保您连接到您认为要连接的人。如果解密您的数据的人是破解者而不是PayPal,加密对您没有任何好处。

The connection is encrypted even if the SSL certificate isn't valid (expired, snake-oil, untrusted CA, etc.). The SSL certificate validation just makes sure you're connecting to the folks you think you're connecting to. Encryption doesn't do you any good if the folks decrypting your data are crackers instead of PayPal.