3 ms·
I don't think this is a problem. If those sites should not be allowed to own the domain names they are using, then the registrars can take the names back. All
by lfam 10y ago
I don't think this is a problem.
If those sites should not be allowed to own the domain names they are using, then the registrars can take the names back.
All the DV certificate means is "you are using an authenticated connection to the server that answers for foo.com".
TLS doesn't have anything to do with the ethics, morality, or legality of the site operators.
It's too bad that we've trained laypeople to think otherwise. But, even a phishing site should be served over HTTPS. Otherwise, the user will be vulnerable not only to the phishing site, but every intermediate server that the connection passes through.