You can always use pihole to mess with your local dns and resolve to a fake website that looks like your social media of choice and collect their password
Hmm good point… you would need the ca to sign off on it self signed doesn’t work… it’s just a file though right? Couldn’t you rip it from the real server?
I mean, we have https now. Also VPNs. Wouldnt this make most situations secure?
You can always use pihole to mess with your local dns and resolve to a fake website that looks like your social media of choice and collect their password
Only if the user ignores the “unsafe connection” warning in the browser, since you won’t have an SSL certificate for the domain
Hmm good point… you would need the ca to sign off on it self signed doesn’t work… it’s just a file though right? Couldn’t you rip it from the real server?