Collected research
Killed by Proxy: Analyzing Client-end TLS Interception Software
A framework for testing the TLS proxies that antivirus and parental-control products insert into a host's traffic, covering root-certificate handling, certificate validation, TLS parameters and client transparency. Of 14 products tested, several accepted forged certificates or had extractable private keys, letting a network attacker impersonate any HTTPS server.
Record
- Researcher
- Xavier de Carné de Carnavalet and Mohammad Mannan
- Published by
- ndss-symposium.org
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Xavier de Carné de Carnavalet and Mohammad Mannan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .