3 ms·
The attacker needs to generate a new cert that the client trusts. This is easy on a corporate network where you can force users to trust a private CA. Unlikel
by Jwarder 7y ago
The attacker needs to generate a new cert that the client trusts. This is easy on a corporate network where you can force users to trust a private CA. Unlikely to happen with a US ISP, but possible if someone hacks the CA (eg DigiNotar) or the CA hands out unconstrained certificates to someone who acts badly (eg CNNIC).
- generalpass 7y agoWhat you are describing doesn't seem to be a MITM attack on https traffic, but something else, which is why I stated "sans CA cert".
- edaemon 7y agoThey're describing what would be required to MITM HTTPS traffic. You're correct that they essentially need to get the cert.
- i2shar 7y agoSpeaking of which, is there a published list of Root CA fingerprints a specific version of OS or browser is supposed to have that I can compare to? In other words, how can one tell if their browser/OS is not compromised with undesirable Root CAs.
- Jwarder 7y agoMozilla and Microsoft publish their lists. Chrome uses the OS's root store. I've seen other open source software use Mozilla's list, but I've never seen a list of what software does that. https://wiki.mozilla.org/CA/Included_Certificates https://wiki.mozilla.org/CA/Included_Certificates https://docs.microsoft.com/en-us/security/trusted-root/participants-list https://docs.microsoft.com/en-us/security/trusted-root/parti...