<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-12-08&#xA;📝 Original message:On Sun, Dec 8, 2013 at 12:40 PM, Drak &lt;drak at zikula.org&gt; wrote:&#xA;&gt; Let me clarify. SSL renders BGP redirection useless because the browser&#xA;&gt; holds the signatures of CA&#39;s it trusts: an attacker cannot spoof a&#xA;&gt; certificate because it needs to be signed by a trusted CA: that&#39;s the point&#xA;&gt; of SSL, it encrypts and proves identity, the latter part is what thwarts&#xA;&gt; MITM. If there was an MITM the browser screams pretty loudly about it with a&#xA;&gt; big threat warning interstitial.&#xA;&#xA;Sadly this isn&#39;t true: There are (many) CAs which will issue a&#xA;certificate (apparently sometime within minutes, though last&#xA;certificate I obtained took a couple hours total) to anyone who can&#xA;respond to http (not https) requests on behalf of the domain from the&#xA;perspective of the CA.&#xA;&#xA;This means you can MITM the site, pass all traffic through except the&#xA;HTTP request from the CA, and start intercepting once the CA has&#xA;signed your certificate. This works because the CA does nothing to&#xA;verify identity except check that the requester can control the site.&#xA;&#xA;If you&#39;d like to me to demonstrate this attack for you I&#39;d be willing—&#xA;I can provide a proxy that passes on :80 and :443, run your traffic&#xA;through it and I&#39;ll get a cert with your domain name.&#xA;&#xA;I&#39;m sorry for the tangent here— I think this sub-discussion is really&#xA;unrelated to having Bitcoin.org behind SSL— but &#34;someone is wrong on&#xA;the internet&#34;, and its important to know that SSL hardly does anything&#xA;to reduce the need to check the offline signatures on the binaries.</html></oembed>