3 ms·
Could you elaborate or do you have a source on the technique you use to mitigate downgrade attacks ?
by yaps8 11y ago
Could you elaborate or do you have a source on the technique you use to mitigate downgrade attacks ?
- ryan-c 11y agoNo mitigation is required. Part of the data signed by the server certificate in the handshake is the entire ClientHello message. If a MitM attacker did a downgrade, they would have to change the ClientHello, and then the client would notice that what the server signed does not match what they sent.