Hacker News new | ask | show | jobs
by justDankin 2093 days ago
Yes! That's a great observation

However, the reason I went for probing the entire path is because the TTL itself can be spoofed

1 comments

Agreed, it's flimsy. Certainly a bit more effort for them spoof it correctly though. Would need to watch traffic on the path back per flow to isolate the number of prior decrements to the TTL leading up to MitM, and then store that value until such time that it sees an SNI it cares about / it's time to generate a reset.