Elektrine lite

← Feed

@shalien@mastodon.projetretro.io

Post #3858088

2026-07-16 12:05 UTC

@joepie91@fedi.slightly.tech If there's no previous established exchange between the two peers there's no mitm. The way you describe things , the attacker would ask the server to establish the connection with him, then reuse the same TLS context for another peer you want to mitm. This would not bring anything but create a TLS connection between the attacker and the server with the victim having it's own TLS context unless the server is mishandling those. A mitm , in classical , would proxy the victim traffic thought himself with its own TLS context that he can spoof since he controls the key exchange and then forward it to the legit server via its own context to it . Attacking before the fingerprint process is done os like telling two people's who didn't said hello to each others yet, hello will imitating one of them.

Replies (0)

No replies.