Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can't an ISP's DNS server tell you that https://www.google.com is at 10.10.10.10? And that is an internal server hosting whatever ISP wants.


They can, but you will get a certificate error, because the ISP doesn't has a valid certificate for the domain.


Exactly. It will show up in any modern browser with a big red "This site is not safe!" type of message if that was to happen. This is one of the reasons Google (and others) so proactively protect the certificate infrastructure so meticulously, and run efforts like https://www.certificate-transparency.org/


Yes, and that is an argument for https with certificates...




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: