Comment on Don't Trust, Verify (or: Validating Origin and Integrity without Public CAs)

<- View Parent
K3can@lemmy.radio ⁨6⁩ ⁨days⁩ ago

Not directly, but I believe mTLS would break if the traffic was intercepted/altered, so it sort of works to test the connection.

mTLS requires installing a certificate on the client device, though. If you’re able to do that, then you’re also able to pin the correct cert or install a custom CA. This would be the “enterprise” solution, as far as I know, but doesn’t work well for public sites, since you can’t always configure your end-users devices.

original
Sort:hotnewtop