Hacker News new | past | comments | ask | show | jobs | submit login

But if you are doing git operations using SSH instead of HTTPS then you aren’t checking domain certs?



It's not about the certs. To execute a man-in-the-middle attack the attacker has to literally put themselves in the middle of the route your packet takes to get to github's servers and intercept it.


Sure, there are many ways an attacker can do that. Not trusting your IP transit is kind of the whole reason for encryption in the first place.

1. Various DNS hijacking and cache poisoning attacks 2. three letter agencies in meet me rooms 3. Exploited/hacked routers 4. Wifi hot spots




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: