
Submission + - When Is a Self-Signed SSL Certificate Acceptable? 5
UltraLoser writes: When is it acceptable to encourage users to accept a self-signed SSL cert? Recently the staff of a certain website turned on optional SSL with a self-signed and domain mismatched certificate for its users and encourages them to add an exception for this certificate. Their defense of this certificate is that it is just as secure as one signed by a commercial CA and because their site exists for the distribution of copyrighted material the staff do not want to have their personal information in the hands of a CA. In their situation is it acceptable to encourage users to trust this certificate or is this giving users a false sense of security?