3 ms·
If this was done by China, would TLS everywhere really have prevented them from performing this attack? Couldn't they perform a TLS MITM, spoofing Baidu to peop
by SoftwareMaven 11y ago
If this was done by China, would TLS everywhere really have prevented them from performing this attack? Couldn't they perform a TLS MITM, spoofing Baidu to people outside the GFoC. They would have the ability to modify the DNS records that show up outside China and certainly would have a CA they, effectively, control to provide a Baidu cert. They could proxy the request through to the real Baidu, then inject the JS to whatever comes back before passing it on. To the user outside China, everything looks copacetic.
It is certainly a more difficult attack, but it doesn't seem like it's outside the realms of possibility for a state actor that funnels all content through one pipe. Am I overlooking something?
- petermonsson 11y agoThe attack would still be possible, but the attacker would now risk their CA status.