Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you sure they weren't using a corporate machine with some sort of MITM proxy? That seems far more plausible than what you're suggesting. Moreover it's unclear why they'd even bother minting a new certificate for the China side, rather than copying the certificate like they do for all their other POPs.


Yeah, I'm sure it wasn't a corporate MITM. I turned off my VPN and saw the same on my own machine.

I guess Cloudflare isn't doing this any more by default.

They probably didn't share the other cert because they'd have to give the private keys to these Chinese partner.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: