2014-04-02 UTC
# ben_thatmustbeme the way this is handled through SSL (validates that you are actually talking to whoever registered the key) is to go to a central repository of public keys and find the one for your site. The assumption is that the SSL registrar is not hacked. SSL keys for the SSL registrar are usually distributed from manufacturers so you know your connection to them is validated