Reply to post: Re: Whooooops!

Apple CORED: Boffins reveal password-killer 0-days for iOS and OS X

Preston Munchensonton
Boffin

Re: Whooooops!

Haha, good luck with that SSL method when the whole of the web goes SSL which is slowly happening.

Actually, that won't matter, since the method in question allows the proxy to act as a man-in-the-middle to decrypt the connections, inspect the contents, and reencrypt the HTTPS connections. They get away with this through the use of an internal CA pushed by default to all internal systems, such that the proxies are always trusted, even when they impersonate external HTTPS sites.

Evil. Pure evil.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon