Skip to content

Comment on Client-side SSL/TLS MITM, compromised CA and server impersonation detection

Comments

Interesting, but doesn't this pretty much assume that the MITM isn't occurring in the last hops of the path to the server?

If all paths (including those through Tor) lead through a piece of compromised infrastructure (a rogue access-point like a pineapple, or subverted router) both will report that the site uses the same certificate despite the MITM.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.