Viewing profile — throwaway66hack
throwaway66hack
HN member- Joined
- Wed, May 22, 2019, 12:08 PM UTC
- HN karma
- 2
- Public activity
- 2 items
- HN profile
- View on Hacker News ↗
About throwaway66hack
No profile information was provided.
Recent public activity
-
comment
Comment #19980748
You are right. With different Tor circuits, the attacker needs to control a lot of exit nodes to correlate the initial HTTP request to ssl-stripped page and the DNS query (to be a …
-
comment
Comment #19980303
How about sslstrip2 ([1], check demo)? A weakness of HSTS is that is stored per domain and the exit node can also control your DNS traffic. I wonder how hard it is to pull this off…