by mad_ady » Sun Dec 21, 2014 4:14 am
Thanks for the link. Currently the wdtv lacks most of the root CAs, and I broght this to b-rad's attention 4-5 years ago (my, how time flies!). I think he never included the full certificates because of firmware space limits, but now, with bi2 support, it shouldn't be an issue...
One thing I don't undestand: is this tracker signed by a root ca (e.g. is the certificate declared valid by a browser?), or does he use some bogus root ca that needs to be added? Adding a bogus root ca totally compromises ssl security (this is how man-in-the-middle attacks are done)
PS. The wdtv has only certificates for netflix (under /etc/certs/ca.pem). I'll try to repace them with something better for the next release