|
|
|
|
|
by tomgirl1
4733 days ago
|
|
Im at a loss, but my first instinct is to say that server certs arent validated properly AT ALL, so I fail to see how client certs would do any better. For all the hype over PFS (perfect forward secrecy) I dont see how how MITM attacks are stopped because cert validation is so bad or nonexistent I dont see applying more certs (plus diffie hellman) to be a solution. |
|
As far as MITM and PFS goes; that's handled just the same as regular SSL. Using a client cert doesn't affect that at all.