4 ms·
Yeah, but your "I know how SSL works" story is probably an NSA plant so that the NSA can read my secretz. NSA NSA blah blah NSA NSA
by blahbl4hblah 13y ago
Yeah, but your "I know how SSL works" story is probably an NSA plant so that the NSA can read my secretz. NSA NSA blah blah NSA
NSA
- klapinat0r 13y agoSuspecious username for a plant-critique "blabla". If you had read any of the CA posts you'd both know why that is the case, and also how easy it would be to test. I can give you a private/public key, certificate, the CA (and password for that) and some traffic I've sniffed while interacting with a webserver, using the forementioned key and certificate. Good luck decrypting the traffic. The only thing you'd be able to succesfully do is pretend that YOUR server is actually mine (and proxy from your server to mine). That's an undetected breach, and an MITM attack. OPs point is still entirely valid. You got my private key from ME, not the CA, and even then you're unable to decrypt the traffic (past).
- grey-area 13y agoYou're really not helping improve the conversation by posting sarcastic responses like this.
- blahbl4hblah 13y agoMaybe I'm trying to communicate my utter contempt for the group-think that's so pervasive on HN regarding privacy....