Hacker News new | ask | show | jobs
by cramforce 2480 days ago
The MITM can be avoided by using Signed Exchanges. https://developers.google.com/web/updates/2018/11/signed-exc...
1 comments

That only works for static content, right?
No, they can be created on the fly. That basically makes it a TLS signing Oracle.