2 ms·
A less common question we get, that a lot of web devs are interested in is 'How do I mitigate against MITM attacks'. - As a browser, by using a default OS and
by mikemaccana 11y ago
A less common question we get, that a lot of web devs are interested in is 'How do I mitigate against MITM attacks'.
- As a browser, by using a default OS and watching the root CA store. You can control the key stores on most devices except iOS pretty easily: https://certsimple.com/blog/control-the-ssl-cas-your-browser-trusts https://certsimple.com/blog/control-the-ssl-cas-your-browser...
- As a server, setting up key pinning (https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning) which throws up a browser warning if someone accesses your site with a new key.
- deleted 11y ago[deleted]