3 ms·
We control the CA so this method of attack is not possible. That said, TOFU is only less secure in practice, not in theory. The "in practice" is because users
by hackmiester 4y ago
We control the CA so this method of attack is not possible.
That said, TOFU is only less secure in practice, not in theory. The "in practice" is because users do not actually compare the cert with anything. They will always just click "Trust."