3 ms·
That's not how it works on a decent VPN system. If you try to do that, the VPN client will notice that the spoofed server isn't presenting a valid certificate
by Wilya 11y ago
That's not how it works on a decent VPN system.
If you try to do that, the VPN client will notice that the spoofed server isn't presenting a valid certificate or doesn't use a valid key, and refuse to connect. Same reason you can't "just" middleman an HTTPS connection.
Besides, there's no need to spoof. The point of the VPN connection is to protect against the wifi router (even the legitimate one!) reading the traffic. By spoofing, you're just replacing a dodgy wifi router with another dodgy router.
- ck2 11y agoIt's extremely easy to middleman a HTTPS connection. Many PC antivirus/firewall programs do it right now.
- mikeash 11y agoPrograms running on your PC can do it because they have access to your certificate store, and can tell the system to trust their certificate. Entities not in control of your PC can't MITM an HTTPS connection, barring a catastrophic bug. And it is catastrophic. If you have a way to do this, please tell everybody because it's going to be the next Heartbleed. The entire point of HTTPS is to prevent stuff like you're describing. And it does work, for the most part. Bugs happen, but they get fixed as they're discovered. It's definitely not "extremely easy." Please go read up on this stuff before speaking authoritatively: https://en.wikipedia.org/wiki/Transport_Layer_Security https://en.wikipedia.org/wiki/Transport_Layer_Security
- ninkendo 11y agoThat's only because the antivirus/firewall products have access to your machine and install a root certificate on them, or more likely, are just using a browser extension to rewrite the dom on the fly. More succinctly, the phrase "man in the middle" kinda loses meaning when the man in question is your own computer.