Hacker News new | past | comments | ask | show | jobs | submit login

So now you can spoof a domain as long as you have the private part of the certificate even though you don't have control over the domain?

If I understand this right then this seems to open up some doors for some new email phishing scams.




This is true with TLS as well, though it also requires man-in-the-middling (MITM) the connection. MITM is usually rather easy compared to stealing a private key.


Yes but it is much harder to MITM if the users are in different parts of the world.

Someone can buy a lookalike domain name using similar-looking UTF characters, send out a bunch of email spam with an URI that looks like the original, and once the user visits the webpage it instantly loads the AMP and suddently the URL is authentic. There will only be a very quick url change from the punycode url to the original that I doubt many will notice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: