Hacker News new | ask | show | jobs
by HackinOut 4139 days ago
TheNextWeb does a poor job at reporting technical facts:

"[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]"

"[...] the certificate allows the software to decrypt secure requests[...]"

As kentonv reported, it's actually the local proxy, installed by the ad(Mal?)ware which is at the center of the MiTM attack. The root, self-signed certificate is installed in order for the attack to be transparent to the victim (i.e. no warning in browser).