3 ms·
In what way are you connecting recent password dumps to hackers attacking Certificate Authorities? If someone controlled the CA, they would also need to control
by dylanfw 10y ago
In what way are you connecting recent password dumps to hackers attacking Certificate Authorities? If someone controlled the CA, they would also need to control the target website and/or the victim's home network in order to MITM the connection and snag the credentials. Also, this would allow them to capture plaintext passwords and as far as I know all of the major password dumps recently have been hashed passwords indicating that the database was breached, not that a CA was compromised and thousands of users were MITMed.