Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can't do passive MITM of TLS if the server is properly configured to use ephemeral key exchange, even if you have its private key. And even without ephemeral kex, and you somehow obtain a secondary trusted CA-signed cert for Steams domain, you still can't do passive MITM.

JS crypto really is worthless if you can't trust the connection.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: