4 ms·
Curious. How do you go about (trivially) defeating asymmetric encryption? EDIT: or do you mean to replace "all" (content + js)?
by klapinat0r 11y ago
Curious. How do you go about (trivially) defeating asymmetric encryption?
EDIT: or do you mean to replace "all" (content + js)?
- venomsnake 11y agoNo, just inject some JS that reads the required keys.
- klapinat0r 11y agoOkay, so it's (just) for reading the delivered data. Somehow I keep considering MitM a harmful attack (i.e. manipulating the data before it hits the user). My bad :)
- angelbob 11y agoCan do that through injected JS as well.
- MatthaeusHarris 11y agoGiven that you're relying on server-provided JS to verify the integrity of the data in the first place, a MITM could replace the verification function with return(true) and then inject whatever data they want.