Videos / Defcon / Aapo Oksman: certmitm — Automated Exploitation of TLS Certificate Validation Flaws

Aapo Oksman: certmitm — Automated Exploitation of TLS Certificate Validation Flaws

Duration: 50min 8sec Type: Presentation (lecture) Playlist: 68 of 146 in Defcon
A DEF CON 31 talk on weaknesses in TLS certificate validation within client applications. Despite the widespread use of TLS, developers often implement certificate checks incorrectly or rely on insecure library configurations.

The researcher introduces certmitm, a tool that automatically detects and exploits these vulnerabilities.

Through real-world examples, the talk demonstrates how such flaws can enable man-in-the-middle (MITM) attacks against applications on platforms like iOS and Windows 11.