Hacker News new | ask | show | jobs
by hueving 3773 days ago
What? How can you get a cert for a domain you don't control?
1 comments

I don't need to control your domain. If I control my own domain, which could be any throwaway domain I just purchased, I can get an SSL certificate on it.

And if I can point your MX records there, via hijack or any other means, then I have a valid SSL certificate for receiving your email.