Now image if the attacker creates a website at 'htt.ps//www.google.com' that resembles google. It has the lock icon. It says 'htt.ps'. I can definitely see this being a problem. People are going to fall for it. Firefox still shows the 'https' before the URL but Chrome does not. People are used to it being both ways.
Comments
And?
`htt.ps` if bought could potentially be weaponized for phishing since it resembles https://
Please note that 'domain hacks' in that sentence does not refer to phishing. [0]
[0] https://en.wikipedia.org/wiki/Domain_hack
You could do something like this:
`https://htt.ps/accounts.google.com/`
Imagine if an attacker own htt.ps
Now image if the attacker creates a website at 'htt.ps//www.google.com' that resembles google. It has the lock icon. It says 'htt.ps'. I can definitely see this being a problem. People are going to fall for it. Firefox still shows the 'https' before the URL but Chrome does not. People are used to it being both ways.