logoalt Hacker News

indoleringyesterday at 6:01 PM1 replyview on HN

Which is really unfortunate, since it's pretty easy to do.


Replies

tptacekyesterday at 6:07 PM

I agree that it's relatively easy for CAs to validate DNSSEC. I think the fact that they weren't technically required to, despite the sole remaining use case for DNSSEC being to protect against misissuance, is a pretty strong indicator of how cooked DNSSEC is.