Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What does having a "well trusted TLS cert" enable for them in this case, exactly?

Having a magical cert doesn't mean you can just intercept everything.



On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"


No, it doesn't. HSTS and other methods prevent this from happening.


HSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine.

No mainstream browser (or any browser?) is doing cert pinning.

What "other methods" are there that are deployed and actually in use?


Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: