| ▲ | echoangle 9 hours ago | |
> don't require messing around with HTTPS certificates. Which also means there’s no real defense against MITM attacks… at least I don’t think anyone seriously checks the host key on first connection. | ||
| ▲ | slowin 9 hours ago | parent [-] | |
You get notified if the server key changes though. I don't think it's fair to say there's no defense against MITM. | ||