
2 Comments to Verisign FAIL – We are all doomed
The reason this is a fail is because the user was presented with an error message at all. Michael J is correct, the two A records point to the same IP address and its not a big deal.
However, by presenting an error message at all we are training the public users to ignore the error message and continue browsing. If they see any other error messages in the future, they’ll be tempted to ignore those as well (and those ssl error messages could be much worse).
If you are using SSL for a site, then there should never be any SSL error warnings presented to the user. > 0 = fail
-Michael Coates
Leave a comment


January 13, 2009
How is this a fail? It’s obviously just a case where two A records point to the same IP address.
No big deal, really.