Hacker News new | ask | show | jobs
by Godel_unicode 3533 days ago
If you can forge certs for HTTPS-protected sites, this is not what you would use them for.
1 comments

It's part of what I would use them for. A big, splashy attack distracts a bunch of people while you MITM something important with a forged cert? Great way to steal a bunch of credentials with something that leaves relatively few traces while the security people are distracted.