what if the hacker provided the public key for https connection?
lostmypasswordanew @ lostmypasswordanew @feddit.de Posts 6Comments 24Joined 2 yr. ago
lostmypasswordanew @ lostmypasswordanew @feddit.de
Posts
6
Comments
24
Joined
2 yr. ago
All TLS/HTTPS clients have a set of Certificate Authority keys which they trust. Your client will only accept a public key which is signed by a trusted CA's key. A proper CA will not sign a key for a domain when it has not verified that the entity that wants it's key signed actually controls the domain.