Hacker News new | ask | show | jobs
by hn-miw-i 4914 days ago
Nokia pushed out an update that uses an http proxy for Phone to server TlS. The worst thing about this is that they have diluted their security model (tls in tls is resistant to single interception-- ie tor).

They did this so boneheads that sniff the traffic will see the phone to server TLS rather than having it encrypted inside the phone to Nokia TLS. That's ignorant "researcher" you actually made it easier for the bad guys now.