from Hacker News

Tell HN: Apple Store wifi attempts https MITM

by gtcode on 10/12/17, 11:57 PM with 4 comments

I was at an Apple Store today, where I browsed an https-only website in Chrome, with which I've been interacting in recent weeks from various access points. No issues in Chrome with the cert up until today. Doing so at the Apple Store today, however, invoked a red 'cert invalid'.

I've just checked the site again in Chrome just now, after leaving the Apple Store, and https is back to green.

Based on the facts, it seems that the Apple Store was trying to MITM the connection which Chrome blocked. Does anyone have any info about this?

If someone at Apple can confirm they do not do this, perhaps someone is running a pineapple-type device at that location, or some Apple Store technician has gone off the reservation, or something else?

  • by jlgaddis on 10/13/17, 3:35 AM

    Without details of the certificate or why it was "invalid" your report is pretty much useless.