Hacker News new | ask | show | jobs
by pbhjpbhj 2451 days ago
Why can't an attacker with router access poison the DNS, redirecting a bank address to the router itself with a fake cert, and duplication of the login screen and steal credentials that way? (Or probably better, steal online MUA [ie email] credentials).

I guess 2FA might block them, but if it were a typed in code you could still get it.