> If your goal is security against passive eavesdroppers - and, in
> particular, against "record everything" government agencies - then a
> self-signed certificate is as good as anything.
> If you want to defend against active MITM attacks, then you need a
> trustworthy certificate.  But as we all know, the current model of hundreds
> of equally-trusted CA's cannot possibly produce legitimate trust.

I was a fan of opportunistic encryption for awhile, but after seeing this,
it started to seem pretty silly to me:


So FUD about CAs aside, without some form of authentication, ISPs (or
anyone with a privileged network position) can and *are* automatically and
trivially stripping opportunistic encryption, rendering it effectively

