|
|
|
|
|
by swiftcoder
2819 days ago
|
|
The spoofer can obtain a valid certificate for another, seemingly legitimate site. Any software that hasn't explicitly pinned the leaf TLS certificates will still accept the (valid) certificate it is redirected to. And sadly, a lot of software still doesn't perform certificate pinning. |
|