Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Their certs may be pinned, but from what I can tell there's nothing keeping me from introducing a new root cert to my system (IIRC there was a scary popup and that's it).

Here's a screenshot of Chrome giving me the "insecure" padlock, but still rendering Facebook while I debug the HTTPS traffic: http://puu.sh/jdGhc/128d35f793.png

Here's similar, showing Google HTTPS traffic being debugged while browsing in Safari (with nothing appearing out of the ordinary): http://puu.sh/jdGoW/3163db1e54.png

(the debugging proxy is Cellist, which I find to be a suitable replacement for mitmproxy, as long as I don't need rewrite/replay)

> if you can trick someone into running an EXE, it's game over

I suppose it is roughly equivalent (i.e. if you could get them to download a cert, you could probably get them to download an EXE so the point may be moot). I always figured you might have more luck with this sort of thing if you owned a Starbucks router or something, where people might be more accepting of having to jump through hoops to use the internet.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: