zlacker

[parent] [thread] 0 comments
1. cesarb+(OP)[view] [source] 2017-02-28 23:21:26
How can a browser distinguish between a self-signed server certificate, and a MITM proxy presenting a self-signed server certificate?

The scary warnings for self-signed certificates are in fact a protection against MITM. It's because of them that MITM proxies are forced to install a CA certificate. The main difference is that installing a CA certificate requires explicit action in the browser (and on some newer systems displays scary warnings), while if a MITM proxy could simply present a fake self-signed certificate, it could easily intercept anyone. Therefore, self-signed certificates are strictly worse.

[go to top]