Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The spoofer wouldn’t be able to obtain a valid certificate for the spoofed site, though.


The spoofer can obtain a valid certificate for another, seemingly legitimate site. Any software that hasn't explicitly pinned the leaf TLS certificates will still accept the (valid) certificate it is redirected to.

And sadly, a lot of software still doesn't perform certificate pinning.


How is this redirect performed?


When a URL is manually typed in, and HSTS or HSTS-preloading isn't enabled, the initial 301 redirect would be http.


It could just be a 3xx redirect over clear http, right? The http site can redirect to a https site with a similar name.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: