3 ms·
So now you can spoof a domain as long as you have the private part of the certificate even though you don't have control over the domain? If I understand this
by rum3 7y ago
So now you can spoof a domain as long as you have the private part of the certificate even though you don't have control over the domain?
If I understand this right then this seems to open up some doors for some new email phishing scams.
- gregable 7y agoThis is true with TLS as well, though it also requires man-in-the-middling (MITM) the connection. MITM is usually rather easy compared to stealing a private key.
- rum3 7y agoYes but it is much harder to MITM if the users are in different parts of the world. Someone can buy a lookalike domain name using similar-looking UTF characters, send out a bunch of email spam with an URI that looks like the original, and once the user visits the webpage it instantly loads the AMP and suddently the URL is authentic. There will only be a very quick url change from the punycode url to the original that I doubt many will notice.