Cert pinning should prevent some of this, but I suspect a lot of Chinese use web browsers downloaded locally (which could compromise pinning; rather than pinning fake certs, I'd just pull the pinning entirely), or browsers which don't support pinning.
I don't think the GFW routinely MITMs HTTPS, but I would be amazed if they didn't do it on a targeted basis against specific sites and users.
And of course if you're using a phone from a state-controlled carrier or a webcafe from someone who complies with pressure, you can be attacked even easier.
Comments
China owns at least one CA.
Cert pinning should prevent some of this, but I suspect a lot of Chinese use web browsers downloaded locally (which could compromise pinning; rather than pinning fake certs, I'd just pull the pinning entirely), or browsers which don't support pinning.
I don't think the GFW routinely MITMs HTTPS, but I would be amazed if they didn't do it on a targeted basis against specific sites and users.
And of course if you're using a phone from a state-controlled carrier or a webcafe from someone who complies with pressure, you can be attacked even easier.