Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you sure? Someone broke into a Hetzner data center and a Linode one, physically intercepted the Ethernet cables for jabber.ru, and got certificates signed on their behalf.

https://notes.valdikss.org.ru/jabber.ru-mitm/

https://news.ycombinator.com/item?id=37961166

 help



dear sockpuppet =) I think the above commenter meant illegal physical access. The jabber.ru MitM situation was likely carried out by a cybercrime unit of the German police forces with a court order... and this is the adversary most people forget about.

Lesson to learn: Let's Encrypt does not protect against MitM by a state-level actor, unless you take precautions. *let's assume network admins won't MitM your server for personal vengeance reasons


> Lesson to learn: Let's Encrypt does not protect against MitM

But S in https stands for secure, or ? /s




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: