Hacker News new | ask | show | jobs
by djrogers 3295 days ago
HTTPS wouldn't prevent this, just harvest the CN and SNI names from the presented cert and use those to match. And as far as changing DNS servers, those can easily be MITMd, or they could just ignore DNS altogether and use a transparent proxy to block/redirect traffic.