Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand, anyone who can MITM can also sniff, right?


Yes they can. They simply decrypt, and reencrypt with their own self signed cert. If you have no way to verify the self-signed cert, you would never know.


An adversary with MitM capability needs to commit to being detectable in order to read encrypted traffic.


but not everyone who can sniff can MITM, encryption always prevents sniffing




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: