|
|
|
|
|
by dijit
3049 days ago
|
|
If you own the machine simply install a CA. Instant trusted everything. Be sure to drop those pesky certificate pinning headers in http though. In fact I believe sslstrip can do all this for you. Including giving it a CA to generate certificates out of. |
|
I assume Tencent's QQ Browser validates certificates properly, but combined with a horrible RSA implementation that's not worth anything. It's actually a more clever (less visible) way of pretending to establish secure/authenticated connections.