Hacker News new | ask | show | jobs
by fierro 1182 days ago
it doesn't take a state actor to MITM this. It takes a Wifi Pineapple advertising a fake AP and tired devs in Blue Bottle smashing `ssh-keygen -R github.com` without verifying the fingerprint. Very simple. Even easier than trying to MITM a site accessed via browser, which will probably have at least HSTS to help you out.
1 comments

Excellent reference to Blue Bottle. I enjoyed visualizing this scenario.