logoalt Hacker News

amiga386today at 4:37 PM1 replyview on HN

MITM where attacker needs to install their own CA certs on the victim's device -- sure, out of scope.

MITM because you used http instead of https and you don't have any other verified cryptographic signature on your data -- get tae fuck, fix it pronto.


Replies

pietervdvntoday at 5:23 PM

I'd even count this as "having local access to the device", as that is what is needed to install such a cert

show 1 reply