|
|
|
|
|
by srdev
5374 days ago
|
|
If Amazon does, in fact, act as a MITM, then that's a deal-breaker as far as I'm concerned. Edit: The more I think about it, the more I think it is likely that they are just passing along the connection. SSL is designed to prevent MITM attacks. They would have to provide their own certificate which would cause browser warnings. They could write their browser to ignore certificate problems for Amazon certificates, but that strikes me as a pretty gaping hole. |
|
If their browser has code operating on the device and in the cloud, then their browser won't generate certificate warnings because there isn’t a man-in-the-middle between their browser and the site, there’s a man-in-the-middle between the device in your hands and the site.
It would be insecure against Amazon snooping or modifying the communication, but still generate the appropriate warnings about bad certificates.
I think the answer is, run “off-cloud” when you want privacy from Amazon.