▲ | nine_k 3 days ago | |||||||||||||||||||||||||
The value: you open such an URL with a bog standard, just-installed browser, and the browser does not complain about the certificate being suspicious. The private key of course stays within the device, or anywhere the certificate is generated. The idea is that the CA from which the certificate is derived is already trusted by the browser, in a special way. | ||||||||||||||||||||||||||
▲ | procaryote 2 days ago | parent | next [-] | |||||||||||||||||||||||||
Compromise one device, extract the private key, have a "trusted for a very long time" cert that identifies like devices of that type, sneak it into a target network for man in the middle shenanigans. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||
▲ | 2 days ago | parent | prev [-] | |||||||||||||||||||||||||
[deleted] |