▲ | lazide 3 days ago | ||||||||||||||||||||||
Not if they have a root cert. | |||||||||||||||||||||||
▲ | viraptor 3 days ago | parent | next [-] | ||||||||||||||||||||||
That's not a property of QUIC. Yes, if you trust both sides, then you trust both sides. That's not what people normally understand as MitM. | |||||||||||||||||||||||
| |||||||||||||||||||||||
▲ | Thorrez 3 days ago | parent | prev [-] | ||||||||||||||||||||||
If China uses a root cert to issue bogus certs, that'll get caught by certificate transparency. Assuming people use browsers that enforce certificate transparency. | |||||||||||||||||||||||
|