4 ms·
it might redirect to a malicious web page, but https would still prevent a problem. perhaps read the article you posted.
by adamconroy 8y ago
it might redirect to a malicious web page, but https would still prevent a problem. perhaps read the article you posted.
- stordoff 8y agoOnly if they are serving HTTPS or HTTPS is pinned. Otherwise, aren't you relying on the user noticing the lack of HTTPS (which I wouldn't want to do)?
- krn 8y agoThe user can just be redirected to another similar looking site with a valid TLS certificate.
- tedunangst 8y agoHow?
- ktta 8y agohttps://gmail.com.inbox-redirect.pro https://gmail.com.inbox-redirect.pro This will seem like a valid website, especially if the phishing site is done well. Not just non-technical users, I'd wager some tech familiar users would be fooled too. The focus always being on the lock icon might not always cover it. Safari will prevent this though.
- aaron_m04 8y agoIsn't that why browsers visually distinguish the TLD and the part before it from the rest of the URL?
- krn 8y agoSSL/TLS downgrade attack when HSTS is not enabled.