Reply to post:

Hacked in a public space? Thanks, HTTPS

Anonymous Coward
Anonymous Coward

SSLstrip substitutes a fake "padlock" icon for the site's favicon. Crude but effective.

"SSL Inspection" proxies the victim through an actual HTTPS connection, so it's less obvious, but the attacker must install their own root cert on the victim's computer (corporate PC, or via malware, or via dumb PC manufacturers) - unless they've obtained the private key for a "real" root cert...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2019