I recall that subdomains are their own record inside a DNS, which would imply that anyone can claim that their server is a non-existent subdomain of the real domain

  • elvith@feddit.org
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 day ago

    Yeah, but now you’re talking about communicating with web.archive.org and not nonesense.reputable-bank.com as in the original post. In this case you’re not even trying to hide the fact, that you aren’t affiliated with reputable-bank.com and we’re back to square one and you could also just use reputable-bank.com.some.malicious-phishing.website to host your page.

    Btw: all modern browsers will warn you when you access a non-encrypted website - some immediately, some only when you try to enter data into a login form.