4 ms·
What does having a "well trusted TLS cert" enable for them in this case, exactly? Having a magical cert doesn't mean you can just intercept everything.
by strictnein 12d ago
What does having a "well trusted TLS cert" enable for them in this case, exactly?
Having a magical cert doesn't mean you can just intercept everything.
- odo1242 12d agoOn the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"
- strictnein 12d agoNo, it doesn't. HSTS and other methods prevent this from happening.
- kelnos 12d agoHSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine. No mainstream browser (or any browser?) is doing cert pinning. What "other methods" are there that are deployed and actually in use?
- peanut-walrus 12d agoTransparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.
- chews 11d ago[dead]
- deleted 12d ago[deleted]