4 ms·
In this case it just acts as a DNS resolver. That's potentially risky when resources don't use SSL, but far less than a browser extension that can change a page
by travisp 8y ago
In this case it just acts as a DNS resolver. That's potentially risky when resources don't use SSL, but far less than a browser extension that can change a page in place, inject JavaScript, and record keystrokes on all pages.
- cremp 8y ago> resources don't use SSL Huh? DNS is hit even if the site is SSL. Unless the site has HSTS, and you've got to the site before; DNS poisoning is very much doable.
- filleokus 8y agoHow would the attacker do anything useful with a SSL connection attempt? They can either send the real certificate, and then not be able to decrypt the data, or send a self-signed cert which the OS/browser wouldn't trust? Are you thinking of some downgrade attack vector?
- emilecantin 8y agoYes, but the hijacker will still need to present a valid cert for that domain, which is much harder.