back

by rietta·12y ago·view on hn ↗
This is very welcome news from my point of view as a developer and security consultant, enough that I blogged about it first thing this morning at http://rietta.com/blog/2014/09/29/universal-ssl-with-cloudfl....

There are industries where off-premises key management is not appropriate and certainly not a trusted man-in-the-middle by a third-party vendor. For these organizations, having any party be in the position to be able to intercept communications is a total no-go.

But for a lot of the internet community that is not the primary threat to model. Rather its inertia that prevents SSL from being set up in the first place because it is seen as either expensive, hard, or somehow unnecessary. For these circumstances, protecting users from criminal surveillance at the local coffee shop and from content manipulation by unscrupulous, unaccountable cable internet service providers is a very good thing.

I have clients who I will advise to pass on this based upon their threat model and others for whom this is a great option. For my own blog, this is perfect too. It's about knowing your threat model and choosing the appropriate countermeasures accordingly.