← All comics

A padlock I made

#082

Russ got tired of renewing the website's security padlock every year, so he made one himself. Every computer in the office started calling the company site dangerous.

The mistake

The site's TLS certificate is self-signed rather than issued by a trusted certificate authority. Browsers and OS trust stores can't verify a self-signed cert against any root of trust, so they flag the connection as insecure regardless of whether encryption is actually working. The fix isn't a homemade cert that 'never expires' — it's automated renewal through a trusted CA (e.g. Let's Encrypt) so the certificate stays both valid and trusted.

Share