[cabfpub] China MITMing icloud.com

Gervase Markham gerv at mozilla.org
Tue Oct 21 16:50:59 UTC 2014


On 21/10/14 15:41, Rich Smith wrote:
> I have no way to independently verify that accusation,

Actually, you do. The cert is here:
http://www.mediafire.com/download/ampbnqncc277krv/fakeicloudcert.zip

And Qihoo 360 is here:
http://int.down.360safe.com/360browser/360browser7.5.2.110.exe

If you have a copy of Windows and the ability to set up an SSL server
and fiddle with your own DNS using a hosts file, you can test it all.

I'm missing the copy of Windows... but I'm eager to hear what everyone
else finds :-)

Gerv



More information about the Public mailing list