Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Erm, where is the danger in a mismatched certificate, if all I want is to get some noncritical information from a blog or something?


Local privilege escalation in your browser is a danger. They can also abuse any privileges you gave to the website, such as camera and microphone.


Why would I give a "random blog" access to my camera or microphon?

And how can a wrong certificate lead to local privilege escalation?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: