Hacker News new | ask | show | jobs
by moondev 3122 days ago
Yikes.. So compromise a public wifi and MITM + store any traffic pointed at the affected domain(s), then simply sign up for their own ERP account, download the key and decrypt.
2 comments

Most public wifi hotspots I've seen are unencrypted, so there'd be no need to do a MitM - just be within range to decode the client and AP transmissions.
Even on an unsecured network would the transmissions not be encrypted via tls from your computer to the server?
Only if PFS is not in use though.