3 ms·
HTTPS still has to resolve the domain name that is part of the url.
by hackits 10y ago
HTTPS still has to resolve the domain name that is part of the url.
- teraflop 10y agoYeah, but an ISP should at worst be able to block connections to specific hosts or IP addresses. If they could generate certificates for arbitrary domains (like thepiratebay.se) allowing them to serve a "blocked for copyright infringement" page over HTTPS, then something would be seriously broken.
- unlikelymordant 10y agoIf it is just at dns, it can just point you to a different ip
- cyphar 10y agoYes, but they won't (or rather shouldn't) be able to get a valid SSL certificate for the domain. This is literally one of the scenarios SSL was created to protect against..
- lokedhs 10y agoThen the browser will refuse to serve the page since the certificate will not match the site you intended to go to. Granted, they'll still stop you from going there but the user won't understand why it fails.
- deleted 10y ago[deleted]