Does turning off CURLOPT_SSL_VERIFYPEER in cURL make transmission insecure? Does turning off CURLOPT_SSL_VERIFYPEER in cURL make transmission insecure? curl curl

Does turning off CURLOPT_SSL_VERIFYPEER in cURL make transmission insecure?


Yes it is insecure. If you don't check the certificate you can't be sure that the sender is truly the server you think you're talking to and it may be an impostor. A man in the middle.

Even impostors can run SSL and negotiate an encrypted connections with you. But they can (supposedly) not purchase a certificate for the forged site using the legitimate cert name.