HTTPS MITM Attacks
The cluster focuses on debates about the feasibility of Man-in-the-Middle (MITM) attacks on HTTPS connections, including certificate validation, browser warnings, corporate proxies installing root certificates, and ISP interference.
Activity Over Time
Top Contributors
Keywords
Sample Comments
Wouldn't this allow them to easily MITM you?
They won't be able to to MITM encrypted connections.
MITM is really absolutely not a Problem here, there is no private data transmitted.
you cant MITM HTTPS unless you're are doing it to yourself for testing.
Shouldn't HTTPS prevent this unless the client has the certificate of the MITMer installed?This being security theatre, it is entirely plausible that the "security" proxy actually decrypted trafic and required the user to have the certificate installed.
Doesn't the browser display a warning in the case of SSL MITM?
MITM scenarios say it isn't :P
You can MITM their connections.
Sorry, should have made it more clear! Basically there’s no need to MITM at all here: https://news.ycombinator.com/item?id=42122270
You can MITM HTTPS, the device just needs to trust the cert (which isn't hard to do)