Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you have a computer between the user and net, then yes all bets are off because you can generate certs the browser will trust.



Only if the root cert store of the user's machine has been tampered with. If you have a valid cert store, you can detect MITM attacks on HTTPS connections.


yep. I was referring to superfish's case.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: