5 ms·
> I would assume that the MITM proxy running on localhost also checks CAs, so what's the problem? (besides breaking cert pinning) Superfish did not check CAs.
by 0942v8653 11y ago
> I would assume that the MITM proxy running on localhost also checks CAs, so what's the problem? (besides breaking cert pinning)
Superfish did not check CAs.
> OF COURSE not. They would just MITM it without crypto stuff. So… it would just be worse.
I think the author is arguing here that the MITM attack wouldn't bother with encrypted traffic (which is obviously a very weak argument).
- the_mitsuhiko 11y ago> I think the author is arguing here that the MITM attack wouldn't bother with encrypted traffic (which is obviously a very weak argument). That SSL interception on computers is on the rise is something every PC game developer can probably attribute to. Right now you cannot pin any certificates any more because of the widespread penetration of SSL intercepting firewalls and antivirus solutions.
- untitaker_ 11y ago>I think the author is arguing here that the MITM attack wouldn't bother with encrypted traffic (which is obviously a very weak argument). I think the author is arguing that SSL requires active eavesdropping, which: 1.) Might break encryption (see Superfish), while the user thinks they're using proper SSL (author argued about the "false sense of security" in a separate section) 2.) Might just break things -- more an argument about software stability than privacy or security.
- thomashabets2 11y agoHuh. Well that's superfish. Surely the norm among big name AV is to check CAs? Or am I being naive? > I think the author is arguing here that the MITM attack wouldn't bother with encrypted traffic (which is obviously a very weak argument) That wouldn't be the case if it was all encrypted, so it's actually a counter-argument.