Earlier quoted context omitted.
if i type https://gmail.com/ into my browser, it usually doesn't matter if you have successfully gotten comodo or actalis to issue you a fake certificate for gmail.com, because my browser doesn't try to connect to your malicious server; it tries to connect to google's actual gmail server, and so you don't receive my packets, and your fake certificate does you no good but, as i said, if you can feed me fake dns result…
because my browser doesn't try to connect to your malicious server Unless a router is compromised along the route, which is a known thing, and part of why we use ssl everywhere now.
the grandparent comment https://news.ycombinator.com/item?id=34629050 also describes some more common ways that this can happen without routers being compromised