14 ms·
On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"
by odo1242 12d ago
On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"
- strictnein 12d agoNo, it doesn't. HSTS and other methods prevent this from happening.
- kelnos 12d agoHSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine. No mainstream browser (or any browser?) is doing cert pinning. What "other methods" are there that are deployed and actually in use?
- peanut-walrus 12d agoTransparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.
- chews 11d ago[dead]
- deleted 12d ago[deleted]