Reply to post: Re: Shut up about the Chinese Cannon and the Verizon Supercookie

Google Chrome update to label HTTP-only sites insecure within WEEKS

Charles 9

Re: Shut up about the Chinese Cannon and the Verizon Supercookie

"In fact, you don't have to be a "state level actor" (TM) to MITM a HTTPS session."

OK, then, explain. How do you MITM an HTTPS session without the private key, without breaking certificate pinning, AND if you've been there before (breaking the First Contact Problem)?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon