Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

STS solves the problem unless the attacker has a fraudulent certificate for the domain you are reaching that is signed by a CA you trust. Presumably this is far fewer attackers than those who could manipulate your DNS or are on your local network to ARP in as a middleman. Basically, two different problems - the trust only X CA for xxx.com wouldn't ever get to come into play if someone using sslstrip simply keeps you from ever going to tls.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: