Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The MITM can be avoided by using Signed Exchanges. https://developers.google.com/web/updates/2018/11/signed-exc...


That only works for static content, right?


No, they can be created on the fly. That basically makes it a TLS signing Oracle.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: