3 ms·
How did they manage to steal coins if they didn't get a valid cert? Did people logging into MyEtherWallet just ignore the invalid cert warnings and log in anywa
by tribune 8y ago
How did they manage to steal coins if they didn't get a valid cert? Did people logging into MyEtherWallet just ignore the invalid cert warnings and log in anyway?
- move-on-by 8y agoCould be, could also be API clients not doing cert validations
- deft 8y agoYes, multiple people on reddit have said that's exactly what they did.
- Already__Taken 8y agoIn addition they could be behind rubbish proxy's that aren't passing the warning forward. I know ours in work will happily resign that expired cert to mitm you for compliance and the user will see that green padlock.
- rocqua 8y agoI get that companies need to control access to their internal networks. But surely when you do it this badly you have to realize you are only making your network less secure.
- tialaramex 8y agoSo far as we've been able to tell all the middleboxes on the market for this sort of purpose are worse than useless. If you remember that NCSC blog post that annoyed Adam Langley, its author Ian Levy insists that "there are some good products out there" I actually replied to that comment, requesting a list of these "good products" which presumably are warranted by the NCSC not to actually be worse than useless. Unsurprisingly Ian has elected not to in fact list any such products. There aren't any.