Earlier quoted context omitted.
> the router would come with a custom burned-in key that it would use to authenticate itself to the CA and get the cert I take apart the router, and get a valid certificate. Now I hijack DNS, and get you to connect to me. HTTPS within LAN for this purpose is useless.
I take apart the router, and get a valid certificate You only get a valid certificate for your router's address. But if you can take apart the router, you don't need to hijack the DNS, you can simply control its traffic. But if you're a guest in my home and I see you take apart my router, you'll have to answer a few questions. Same in an office or coffeshop. Having LAN access doesn't mean you have complete physical c…
Considering basically every router has the same address, I now have a valid certificate for basically every router.