What is stopping a scammer from HTTPS certificating a "nonsense.ReputableBank.com"
redpotatoes @ redpotatoes @lemm.ee Posts 0Comments 2Joined 2 yr. ago
redpotatoes @ redpotatoes @lemm.ee
Posts
0
Comments
2
Joined
2 yr. ago
They'd need a certificate authority to issue the certificate, and the victim's browser would have to trust that authority.
Edit: and the scammer would need to control the domain DNS server to use the subdomain, like another reply said, so the certificate alone wouldn't help much.