Earlier quoted context omitted.
No, TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, or b) the attacker successfully forges the certificate of the website you are trying to visit. That is, assuming you don't click away your browser's security warning. https://security.stackexchange.com/questions/8145/does-https...
> TLS is not vulnerable to a MITM unless a) your client trusts the certificates issued by the attacker, Or in other words it is vulnerable. China can (and probably does) issue a certificate that all Chinese browsers must install, they can then do MITM https using their certificate to sign the new versions. Companies do this routinely BTW. Since it's their equipment, it's considered just fine. (But be aware of it if y…
I've never seen or heard of this (at least across all browsers), so I find this unlikely.