Hacker News new | ask | show | jobs
by pcthrowaway 897 days ago
On Mac (which the author appears to be talking about), I believe agreeing to Always Trust when connecting to a WPA3 network only enables it for the "X.509 Basic Policy" setting. I don't know much about how the different trust policies on OSX work though, and it makes me very uncomfortable that trusting self-signed root certificates may become more common for connecting to wifi networks.

If you do trust the root cert for everything, couldn't the access point MITM all your traffic?

1 comments

Not only MITM traffic, but also run arbitrary software since it could also govern code signing.