Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Credentials are sent BEFORE prompting the user to accept a self signed cert. So it sounds like an attacker can harvest credentials on a rogue wifi by spoofing DNS and using a self-signed cert. I don't have an iOS device so I can't test.

This does not appear to be the case (Tested on an iOS 10.3.3 device and an iOS 11 device).



Thanks for confirming. So then there is nothing at all of substance in this article.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: