jeudi 15 janvier 2015

What does this mismatching SSL certificate hint at?



So I'm currently visiting China, and I use a well known VPN service for both my laptop and my phone.


Every now and then, I get certificate errors when using my phone when I'm connected to a VPN, but this never happens on my laptop.


Currently I'm trying to access m.facebook.com and I get a warning that the certificate is mismatching. I have one here now that says that the certificate presented belongs to someone with a "common name" that is a ip address that goes to a hosting provider in Germany. I get this both while being connected to a Hong Kong and a Taiwan VPN server.


How suspicious is this? Could it be a honest mistake somewhere in the chain? Why do I only get these errors when I'm using my phone, and never my laptop? If this is an attempted attack, what could be compromised?





Aucun commentaire:

Enregistrer un commentaire