Hacker News new | past | comments | ask | show | jobs | submit login

Because the BROWSER is what's being attacked in a MiTM. To the server it just looks like a regular client connecting. It never sees the certificate the client saw. There is nothing for the server to reject.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: