So does TLSI break VPNs? Or would that only work if the CA is faked?
SpaceLifeForm •
@ Curious
“What would be the difference between so called “TLS inspection” and hacking/cracking?”
Money, time, resources.
Big players have that.
Hackers, script kiddies, not so much.
SpaceLifeForm •
@ Pocono Chuck
Yes. And Yes.
Weather •
@Pocono Chuck
If they have the private key, they can decode the traffic from the handshake etc, if you are asking if someone is parrellel not actual mitm then you can as a attacker make them use you key, but if you are mitm and give the client and website your key, they will have to use other means to detect the tap, one send them wrong encryption data with TTL or number of hops before drop and if it disappears. Set the MTU max trimsion unit to a low value and see if the webserver asks to increase it, and also timing. If the webserver is under you control, you can set up a verification system, not necessary using know each public key. You can use the webserver selection of port number, well client to workout os