3 ms·
You can actually analyse most ssl traffic with a man in the middle proxy. All you need to do is to reencrypt the the data with your own certificate and accept t
by nicothieb 14y ago
You can actually analyse most ssl traffic with a man in the middle proxy. All you need to do is to reencrypt the the data with your own certificate and accept to signing certificate as trusted on your computer.
SSL is not obfuscation, it is about maintaining a chain of trust.
- rogerbinns 14y agoI've written one of those before(1). For general browser traffic it isn't problem since you can add the proxy cert to the browser or whatever it uses. For apps (ie non-browser) it will depend on their certificate checking code, which for best practise should not accept any old gunk the OS/browser does. (1) For a test I used my bank which had all sorts of RSA checked and similar logos all over the "secured" pages. Needless to say those logos remained even though I was going through a man in the middle.