TLS interception considered harmful (camp2015)
Update: 2015-08-16
Description
With the more widespread use of encrypted HTTPS connections many software vendors intercept these connections by installing a certificate into the user's browser. This is widely done by Antivirus applications, parental filter software or ad injection software. This can go horribly wrong, as the examples of Superfish and Privdog have shown. But even if implemented properly these solutions almost always decrease the security of HTTPS.
about this event: https://events.ccc.de/camp/2015/Fahrplan/events/6833.html
about this event: https://events.ccc.de/camp/2015/Fahrplan/events/6833.html
Comments
In Channel




