Skip to content

Comment on Tails 2.0 is outparent

Comments

Yes it must, because self-signed carts offer no defense against MITM.

To be more precise, they offer no defense against MITM on first visit. Once I've pinned a particular self-signed cert for a particular site, I'll be quite suspicious if that cert ever changes.

Okay, but that only helps the tiny subset of HNers who are manually pinning certs for a random website.

Further, real world MITMs are ad injection at the device (Lenovo Superfish) or ISP level, so they are persistent.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.