How can the MITM present the correct server certificate to the victim?
This problem is not mentioned at all in all the papers I skimmed, so this
is probably just me being daft.
Posted Dec 3, 2009 0:10 UTC (Thu) by xoddam (subscriber, #2322)
[Link]
As I understand it, the certificate exchange is still between the client and the server; the MITM does nothing more than forward the data and insert a cleartext payload into a window of vulnerability. In this attack, the MITM does not need to know or have any certificate or cipher keys.