Cert pinning should prevent some of this, but I suspect a lot of Chinese use web browsers downloaded locally (which could compromise pinning; rather than pinning fake certs, I'd just pull the pinning entirely), or browsers which don't support pinning.
I don't think the GFW routinely MITMs HTTPS, but I would be amazed if they didn't do it on a targeted basis against specific sites and users.
And of course if you're using a phone from a state-controlled carrier or a webcafe from someone who complies with pressure, you can be attacked even easier.
Comments
How were they able to sniff your keywords on Gmail chat? I thought as long as you are connected via HTTPS, your packets are encrypted.
Or does China not allow connecting to foreign websites via HTTPS?
China owns at least one CA.
Cert pinning should prevent some of this, but I suspect a lot of Chinese use web browsers downloaded locally (which could compromise pinning; rather than pinning fake certs, I'd just pull the pinning entirely), or browsers which don't support pinning.
I don't think the GFW routinely MITMs HTTPS, but I would be amazed if they didn't do it on a targeted basis against specific sites and users.
And of course if you're using a phone from a state-controlled carrier or a webcafe from someone who complies with pressure, you can be attacked even easier.