Hacker News new | ask | show | jobs
by FreeFull 3305 days ago
This is feasible, assuming the government is willing to pay for the hosting.
1 comments

As well as forge an SSL certificate for *.wikipedia.org.

Last time I checked, Wikipedia had HSTS enabled. So trying to forge their DNS without also forging their SSL certificate would be equivalent to total censorship for anybody who has previously visited Wikipedia.

Assuming the government in question has access to a root certificate this should be possible.
Even presuming it is possible, it still raises the cost of censorship. Simply raising that cost is a good thing.