Comments

Carl Fink August 17, 2026 8:10 AM

Would that be compatible with https? Would the fake login page not have the wrong cert, if it even had SSL enabled? Or is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something?

Andrew Olpin August 17, 2026 9:32 AM

Yes, the DNS would direct them to the wrong server, and the attacker could HTTPS encrypt the traffic. The trouble is that no reputable cert issuer will issue some rando a cert for “google.com,” so it’s very likely the certificate won’t be trusted by the browser.

My guess is the attackers will go for HTTP and hope the user doesn’t notice.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.