Skip to content

Comment on 'Trivially easy' to buy SSL certificate for domain you don't own

Comments

Once you have a SSL cert for a domain you don't own, to use it you'd need to be able to host content on a domain you don't own. Surely this makes this kind of attack less viable?

With such a cert, you can carry out a man in the middle attack without triggering SSL warnings (in the typical usage model for SSL), because you have a valid cert.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.