Earlier quoted context omitted.
In the case of DDG, that would be difficult. DDG uses SSL. If you make a mistake and type "duckduckgo.com" instead of " https://duckduckgo.com" , it will automatically redirect you to the secure page. Unfortunately, that redirect gives a man-in-the-middle and opportunity to hijack your connection, even with SSL; however, that's tricky enough that its hard to imagine anyone pulling it off without ever being noticed.
>Unfortunately, that redirect gives a man-in-the-middle and opportunity to hijack your connection, even with SSL As long as the SSL cert isn't compromised, I don't see how this is possible.
So rather than being redirected to a secure connection, I happily communicate with the attacker instead.