Once you have a SSL cert for a domain you don't own, to use it you'd need to be able to host content on a domain you don't own. Surely this makes this kind of attack less viable?
With such a cert, you can carry out a man in the middle attack without triggering SSL warnings (in the typical usage model for SSL), because you have a valid cert.
Comments
Once you have a SSL cert for a domain you don't own, to use it you'd need to be able to host content on a domain you don't own. Surely this makes this kind of attack less viable?
With such a cert, you can carry out a man in the middle attack without triggering SSL warnings (in the typical usage model for SSL), because you have a valid cert.