misskey-hub-next icon indicating copy to clipboard operation
misskey-hub-next copied to clipboard

Domain is unavailable (MITM) Unencrypted/decrypted by third party

Open spirillen opened this issue 11 months ago • 5 comments

💡 Summary

Domain is unavailable (MITM) Unencrypted/decrypted by third party and it is encoring who have non-free access to the contents of your domain.

🥰 Expected Behavior

END to END encrypted connection as implied, it should be encrypted by certificate and not eardropping by MITM, that fingerprint and PII registration.

🤬 Actual Behavior

The false certificate simulates a secure connection, but the connection is NOT secure.

The MITM censoring fingerprinting secured browsers/Connection from accessing the domain

The MITM Are decrypting the connection (MITM), collect PII data whitout warning or any other kind of information about this to the visitor.

image

📝 Steps to Reproduce

  1. Try visit https://misskey-hub.net/
  2. You are cencored (Blocked) by MITM
  3. MITH tries to fingerprint you, to collect PII data, without asking or informing the visitor about this (GDPR violation)

💻 Environment

* Model and OS of the device(s): Any
* Browser: Any with privacy in mind, such as Firefor-ESR (+ Tor browser)

(For developer) Do you want to address this bug yourself?

  • [ ] Yes, I will patch the bug myself and send a pull request

spirillen avatar Mar 17 '24 12:03 spirillen