• diabetic_porcupineBanned
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    2
    Aquileo | arrow-down
    1
    ·
    1 month ago

    You can always use pihole to mess with your local dns and resolve to a fake website that looks like your social media of choice and collect their password

      • diabetic_porcupineBanned
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        1
        ·
        1 month ago

        Hmm good point… you would need the ca to sign off on it self signed doesn’t work… it’s just a file though right? Couldn’t you rip it from the real server?

        • Anivia@feddit.org
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          1
          ·
          1 month ago

          it’s just a file though right? Couldn’t you rip it from the real server?

          No, that’s not how TLS works. The certificate is not exposed to the internet unless the admins of the webserver are extremely incompetent. That would defeat the entire purpose, not only could you impersonate the server, but the encryption would also be futile since anyone would have access to the private key.