Skip to content

Comment on We need a “/heartbleed.txt” standard, and we need it ASAPparent

Comments

jikOP

MITM attacks require far more sophistication and many more moving parts than just stealing data from a web server's memory. Just because you have the SSL cert's key doesn't mean you have the ability to use it to MITM a site.

I'm not saying what you propose is impossible; I'm just saying it's quite unlikely. Security is all about layers. You don't throw away a layer that could be effective at increasing security in the majority of cases just because there are some cases where it wouldn't work.

Of course. You can't MITM all the traffic to the site. But if hackers are targeting a certain security-conscious user, this standard will give them another tool!

This new layer will make the security better for the average user, but it will enable attackers to make a website look falsely patched in a MITM attack.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.