Comment Re:Worth it. (Score 1) 733
The issue isn't poor security. Using ssl/tls with a self signed certificate is more secure than passing all communications in the clear. With recent news Why One-time Passwords Suck For MITM Attacks one wonders what we are getting by trusting the CAs. Note in the article that a researcher was able to get a certificate for login.live.com so he now has a CA IE will accept. The real security issue is that by making it difficult/expensive for the small web service to get a valid certificate from a CA that both IE and Firefox accept and providing a warning screen that will cause some users to avoid the service, we will get services that use no encryption. Since we all know that a large portion of the web using community use one password for all their services, this makes these sites an easy resource for harvesting credentials.