Not condoning the practice, but thats my guess at the motivation. I also imagine it doesn't work very well, as many new browsers will refuse to display if the cert chain is broken.
Not condoning the practice, but thats my guess at the motivation. I also imagine it doesn't work very well, as many new browsers will refuse to display if the cert chain is broken.
https://twitter.com/__apf__/status/551132865555996673
EDIT: Still from same author:
no, had already been logged in for hours; and only happened on YouTube
The fact that the screenshot shows they are not rediecting with the fake cert makes it clear this is an intentional Man in the Middle attack.
Why does no-one ever seem to use 802.11u for this?
The most probable explanation is that it's a "transparent" proxy which MITMs everything, and the original poster used youtube as an example.
My guess is caching (thats in airplane).