|
|
|
|
|
by wvs
4945 days ago
|
|
The core issue is that encryption is useless without authentication. A MITM could just replace the original self-signed certificate with his own and read the decrypted plaintext while proxying the request so the user doesn't notice. |
|