4 ms·
From what I can see this uses the same public/private key for everyone using the service. So it would be easy to MITM any HTTPS connection using this if you're
by omh 11y ago
From what I can see this uses the same public/private key for everyone using the service. So it would be easy to MITM any HTTPS connection using this if you're a network admin or hostile WiFi etc.
I don't think this is a problem for the intended audience - developers and test sites.
But there should perhaps be a clear warning somewhere about not using this in production.
EDIT: Turns out this is actually mentioned on the FAQ page of https://sslip.io/ https://sslip.io/
- JosephRedfern 11y agoI'm not suggesting that this makes it acceptable to use in production - but am I right in thinking that you'd be unable to MITM the connection if the server/client both support perfect forward secrecy?
- brohee 11y agoSomeone that intercepts the traffic act as a proxy and will just PFS with the client and the server. Confidentiality should be ensured by PFS if the attacker is only sniffing. But so many scenarios where even an unsophisticaded attacker can do more that is is not worth thinking about.
- JosephRedfern 11y agoThat makes perfect sense - thanks.