logoalt Hacker News

micwyesterday at 9:07 AM1 replyview on HN

If the load balancer can force a downgrade, an attacker can do it as well.


Replies

jeroenhdyesterday at 10:15 AM

Only if the attacker has a valid certificate for the domain to complete the handshake with.

Relying on HTTPS and SVCB records will probably allow a downgrade for some attackers, but if browsers roll out something akin to the HSTS preload list, then downgrade attacks become pretty difficult.

DNSSEC can also protect against malicious SVCB/HTTPS records and the spec recommends DoT/DoH against local MitM attacks to prevent this.

show 2 replies