3 ms·
Of course you can -- for example, if you are NSA and in position to apply pressure to whoever hosts lastpass SSL frontends.
by jsn 13y ago
Of course you can -- for example, if you are NSA and in position to apply pressure to whoever hosts lastpass SSL frontends.
- icebraining 13y agoIf you're the NSA, you can probably get a CA to sign a cert for you, no need to steal theirs. But MITM can still affect a lot of people if the attacker can get into a big gateway (e.g. large company, ISP, university, etc).
- Xylakant 13y ago> If you're the NSA, you can probably get a CA to sign a cert for you, no need to steal theirs. That would leave a trace (at least the person issuing the cert would know) while heartbleed doesn't.