> If so, then they fire up Nginx and serve poisoned PDFs to anyone who connects to it.
Even if the attacker redirects the traffic, it still needs to serve the HTTPS/SSL certificates. How will the attacker do that?
Even if the attacker redirects the traffic, it still needs to serve the HTTPS/SSL certificates. How will the attacker do that?
EDIT:
Specifically: https://letsencrypt.org/docs/challenge-types/
It won't give you a wildcard certificate, but you don't need one for the type of attack we're talking about.
There are a lot of ways this could go wrong.