View Single Post
  #14  
Old Jun 19, 2016, 01:05 AM
ibmibmibm ibmibmibm is offline
Junior Member
 
Join Date: Mar 2012
Posts: 4
Default

There's a protocol that defending Man-In-The-Middle attack over https, called [HPKP](https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning).
This is done by adding a certification hash value in the HTTP response header, and the browser will record this hash in a specified period.
Reply With Quote