Ask HN: HTTPS and SSL Proxy security question

Ask HN: HTTPS and SSL Proxy security question
3 by fakeElonMusk | 1 comments on Hacker News.
I'm not a security expert but I always thought that HTTPS was secure and that if my code was calling an API (for example) with HTTPS/SSL Cert that it was encrypted end to end. Rephrase, I know it's encrypted but I'm aware that MIM or SSL Proxy methods can be used to expose that traffic by spoofing client/server keys. So I assume that someone has to be on your network to use a tool like Charles Proxy. Is the combination of securing your network plus HTTPS "enough" security to keep web and app traffic safe? What are other aspects I'm missing? Would love to learn more if anyone is willing to share some good resources. TIA.

Comments

Popular posts from this blog

Lord of the Rings Influenced a Cyberpunk 2077: Phantom Liberty Quest

Lord of the Rings Fans Mourn King Théoden Actor Bernard Hill, Dead at 79

Redfall's Final Update Is Live, Bringing With It Offline Mode, DLSS 3, and More