▲ 353 ▼ North Korean infiltrator caught working in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location (www.tomshardware.com) submitted 9 months ago by sqgl@sh.itjust.works to c/technology@lemmy.world 50 comments fedilink hide all child comments https://archive.is/sfYWG
[–] BrianTheeBiscuiteer@lemmy.world 5 points 9 months ago (3 children) This is definitely a thing. permalink fedilink source parent hideshow 3 child comments replies: [–] EncryptKeeper@lemmy.world 1 point 9 months ago (2 children) Only if the site they’re visiting isn’t using HSTS, but it’s possible permalink fedilink source parent hideshow 2 child comments replies: [–] foobaz@lemmy.world 3 points 9 months ago (1 child) I don't think this is correct. HSTS only prevents downgrading. permalink fedilink source parent hideshow 1 child comment replies: [–] ShellMonkey@piefed.socdojo.com 2 points 9 months ago HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps. permalink fedilink source parent
[–] EncryptKeeper@lemmy.world 1 point 9 months ago (2 children) Only if the site they’re visiting isn’t using HSTS, but it’s possible permalink fedilink source parent hideshow 2 child comments replies: [–] foobaz@lemmy.world 3 points 9 months ago (1 child) I don't think this is correct. HSTS only prevents downgrading. permalink fedilink source parent hideshow 1 child comment replies: [–] ShellMonkey@piefed.socdojo.com 2 points 9 months ago HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps. permalink fedilink source parent
[–] foobaz@lemmy.world 3 points 9 months ago (1 child) I don't think this is correct. HSTS only prevents downgrading. permalink fedilink source parent hideshow 1 child comment replies: [–] ShellMonkey@piefed.socdojo.com 2 points 9 months ago HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps. permalink fedilink source parent
[–] ShellMonkey@piefed.socdojo.com 2 points 9 months ago HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps. permalink fedilink source parent