4 ms·
It depends on whether or not the client specifically requested, or is expecting, traffic over HTTPS. But yes, if the user's client requests encrypted traffic, t
by simulate-me 4y ago
It depends on whether or not the client specifically requested, or is expecting, traffic over HTTPS. But yes, if the user's client requests encrypted traffic, the attacker will not be able to produce a valid certificate. This attack isn't that different than a MITM.
- tedunangst 4y agoNothing prevents an attacker from getting a cert for snytimg.com or oslashdot.org.
- legalcorrection 4y agoThat only helps the attacker if the error happened before reaching the DNS-specific path. If the error happens inside the DNS path, then the browser is still expecting to get a certificate for the correct website.
- tedunangst 4y agoIf the error happens inside the DNS path, the name in the answer won't match the name in the query. The browser is still expecting to get an answer for the hostname it sent.
- deleted 4y ago[deleted]