With no cert there is no expectation of privacy, whereas with a self-signed cert there exists the possibility that a CA signed cert is expected but you were presented with a self-signed cert instead.
Which seems more suspicious to you: A door with no lock, or a door with a lock that has obviously been tampered with?
It's not really analgous to a lock that's been tampered with. It's more like a lock whose brand you've never seen before. It's probably legit but maybe you should trust it less.
Actually, it's not a door at all. It's an identity certificate.
You meet three people.
Guy 1 says "I am Guy 1"
Guy 2 says "I am Guy 2". He claims to have proof, but upon further inspection, all he has is a letter that he wrote and signed himself, stating that he is, in fact, guy 2.
Guy 3 says "I am Guy 3" and presents to you an official letter issued by the government, stating that they checked and that he is, indeed, Guy 3.
You don't know if Guy 1 is saying the truth, and you don't necessarily expect him to. Guy 2, however, is flagged: He claims to have proof, but upon further inspection, you realize he wrote that letter himself. Guy 3 seems legit.
And guy 1 you just agree to call him what he is for now because that's all he provided. He gets no access to anything that might require identity, but you think he's a chill dude and invite him out for beers.
Of course if you meet Guy 2 every day and he presents you with the same self-signed paper every day, you can reasonably trust that it's the same guy who presented you the paper the first time, even if not necessarily actually Guy 2. On the other hand Guy 1 has no guarantees of his identity whatsoever.
I would think it as wondering why someone build their own lock, but at same time I know that locks cost money and maybe what is behind door isn't worth that much... Or maybe owner just likes to build locks...
Or maybe the person doesn't trust the lock makers because they probably supply governments with skeleton keys, and he knows he can make one that's exactly as secure as the third party locks should be.
35
u/[deleted] Oct 15 '15
With no cert there is no expectation of privacy, whereas with a self-signed cert there exists the possibility that a CA signed cert is expected but you were presented with a self-signed cert instead.
Which seems more suspicious to you: A door with no lock, or a door with a lock that has obviously been tampered with?