Hacker News new | past | comments | ask | show | jobs | submit login

Yea, if someone at a nation state level manage to fake a cert and redirect BGP, I'm sure they could affect a huge number of systems pretty quickly. Do git clients even do a good job of SSL verification?



China briefly blocked GitHub (for whatever reason) and the tech establishment screamed bloody murder.

I cannot even begin to imagine how it would react to it being MITM'd.


afaik git doesnt do ssl verification.

its supposedly being handled by either ssh or libcurl

or are you talking about these frontends like source tree, smartgit, ... ?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: