2 ms·
> The scenarios you listed can even make HTTPS insecure. You don't understand what HTTPS does, then. HTTPS is specifically designed to counter MITM attacks, s
by labcomputer 3y ago
> The scenarios you listed can even make HTTPS insecure.
You don't understand what HTTPS does, then.
HTTPS is specifically designed to counter MITM attacks, so it is, in fact, not insecure in the scenarios listed by the parent comment.
> If you were visit that page on an network that is not MiTM the website is still secure. There is no requirement for SSL.
That is really only relevant when you and your sever are on the same LAN, behind a firewall, and you are reasonably sure that you don't have an intruder (like I mentioned upthread).
When you are browsing a server across the public internet, you should assume you are being MITM'd. With HTTP (not S), the MITM attacker does not need to be between you and the server. If they can guess the TCP sequence number and when you are browsing, the MITM can inject (or replace) arbitrary content into the pages you load.
- doublerabbit 3y agoYes, and with those scenarios if your root certificate has been maliciously modified https isn't going to save you either