DNS server points to a fake web host, which performs the fetch and modifies in stream for the client. Is getting a cert the issue here? I don't think so.

Comments