|
|
|
|
|
by KirillPanov
973 days ago
|
|
Easier to conceal the attack. The MiTM attacker can pass through a command stream without STARTTLS. If they intercepted 5223 they would have to do their own client-side TLS handshake with the attacked server, which would look really obvious to anybody doing TLS fingerprinting on the server: all of a sudden, 100% of their clients have the exact same TLS fingerprint. Stop outsourcing your PKI to ICANN, folks. Domains are not public keys. |
|