Hacker News new | ask | show | jobs
by Jon_Lowtek 2174 days ago
FinFisher has "drive by infection" packages for sale called FinFly that require traffic injection, according to their brochure. How exactly those work today, i do not know. For example: until 2011 they used a bug in the self update code of iTunes. Having a network level man in the middle can benefit many complex exploit chains.
1 comments

I hope someone sees this and can enlighten us on how the technique currently works with TLS being more prevalent.