What makes SSL secure?

后端 未结 4 1595
名媛妹妹
名媛妹妹 2021-01-14 23:11

I\'ve been reading a few sites on the internet on how SSL works, but I don\'t understand how exactly it makes things secure. Probably because I don\'t understand completely

4条回答
  •  栀梦
    栀梦 (楼主)
    2021-01-14 23:42

    surely an encryption key needs to be shared. If someone is eavesdropping on your connection, wouldn't they just be able to grab this key

    No. The key is never transmitted. It is computed at both ends independently via a key-agreement algorithm.

    What prevents a rogue server from faking a certificate signed by a root certificate provider?

    The certificate is sent along with its digital signature which is made with the private key, and verified by the peer via the certificate's own public key. The server would need the private key of the server it is spoofing.

提交回复
热议问题