logoalt Hacker News

coretx11/21/20242 repliesview on HN

Because SNI. Also, State (sponsored) Actors are certificate authorities. HTTPS is the biggest scam in internet history. https://en.wikipedia.org/wiki/Server_Name_Indication


Replies

astrange11/21/2024

This certainly was an issue but it's solved by ECH/DoH. As long as they aren't blocked on your network anyway.

> Also, State (sponsored) Actors are certificate authorities.

To generate a fake certificate as a CA you have to either put it in the Certificate Transparency log, in which case everyone will notice, or don't, in which case browsers will notice (they know what top sites' certificates are supposed to look like) and your CA will get shut down.

show 1 reply
account4211/21/2024

SNI doesn't expose headers and request paths.