Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

And you know the NSA hasn't been given or stolen SSL private keys of major players?

Most big sites don't use forward perfect secrecy making MITM achievable.



MITM always unambiguously refers to an active attack. That's not what they do or have ever done. It stands for man-in-the-middle. They aren't in the middle when they tap fibers.

Lack of forward secrecy ciphersuites does allow for retroactive decryption upon server secret key compromise though, which is what I assume you meant.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: