3 ms·
the attacker MITM TLS has to present a certificate for the spoofed domain that was signed by a Certificate Authority the victim's browser trusts
by theEXTORTCIST 9y ago
the attacker MITM TLS has to present a certificate for the spoofed domain that was signed by a Certificate Authority the victim's browser trusts
- discreditable 9y agoVery easy to do. You can even automate it with Let's Encrypt since you can serve whatever DNS records you want.