Y
Hacker News
new
|
ask
|
show
|
jobs
by
Mawaai
4197 days ago
Well, if you can intercept the request to the server to can also change that parameter of the TLS certificate hash.
1 comments
neftaly
4196 days ago
Is that actually true, though (especially w.r.t. Forward Secrecy)? Don't both parties generate separate halves of a symmetric key independently, preventing any one party from forcing the use of a particular key on a new session?
link