For 3b) you're relying on the broken Certificate Authority system of PKI; you're "trusting" that your browser or OS is using only authentic […]