It's interesting to note that, although in this case the HTTPS certificate presented by the attackers wasn't valid, they may have been able to acquire an apparently legitimate certificate if the misrouting's effect extended to the infrastructure of a certificate authority.
Comments
It's interesting to note that, although in this case the HTTPS certificate presented by the attackers wasn't valid, they may have been able to acquire an apparently legitimate certificate if the misrouting's effect extended to the infrastructure of a certificate authority.