|
|
|
|
|
by burtonator2011
2785 days ago
|
|
This is one of the reasons TLS/SSL and crypto is so amazingly important. Go ahead, monkey around with BGP, since I have the public key of the recipient of my packets I can detect this and block any type of misdirection. |
|
And how did you get that public key?
An attacker could pretty easily obtain a valid Let's Encrypt certificate using a BGP hijack.
Also, the CA system is in bad shape - CAs have been hacked and certificates were leaked. Not to mention that some of the CAs your browser trusts are not entirely trustworthy or are located in untrustworthy countries. Oh, and from time to time there are attacks against TLS itself (e.g. https://drownattack.com/)