Earlier quoted context omitted.
"I use arbitrarily complex software that has a rapid SDLC to obfuscate the issue with the fact that we have to have military grade encryption for displaying the equivalent of a poster over the internet". The state of our industry is such that there will be a lot of people arguing for this absurdity in the replies to me. (or I'll be flagged to death). Package integrity makes sense, and someone will make the complicate…
Changing the links and doing nothing else would be a pretty dumb MITM. You could do a more complex variant which is not so easy to spot (targeting specific networks, injecting malware whilst modifying the checksum) The key property of SSL that is useful for tamper resistance is that it’s hard to do silently. A random ASN doing a hijack will cause an observable BGP event and theoretically preventable via RPKI. If your…
Not when you control the certificate issuer.