3 ms·
it's fair to say they do and have for ages... it's not that hard to assume a well trusted TLS cert is under their control.
by chews 22d ago
it's fair to say they do and have for ages... it's not that hard to assume a well trusted TLS cert is under their control.
- strictnein 22d agoWhat does having a "well trusted TLS cert" enable for them in this case, exactly? Having a magical cert doesn't mean you can just intercept everything.
- odo1242 22d agoOn the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"
- strictnein 22d agoNo, it doesn't. HSTS and other methods prevent this from happening.
- kelnos 22d agoHSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine. No mainstream browser (or any browser?) is doing cert pinning. What "other methods" are there that are deployed and actually in use?
- peanut-walrus 22d agoTransparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.
- chews 21d ago[dead]
- deleted 22d ago[deleted]