logoalt Hacker News

amiljkovictoday at 4:55 PM1 replyview on HN

The Ars article mentions: “Even when HTTPS is in place, an attacker can still intercept domain look-up traffic and use DNS cache poisoning to corrupt tables stored by the target’s operating system.” Not sure, but I think this could then be further used for phishing.


Replies

jcalvinowenstoday at 7:49 PM

DNSSEC prevents that if set up properly.