logoalt Hacker News

cyberaxtoday at 3:46 AM2 repliesview on HN

It does solve it. Unless you know my private key, you can't fake the DNSSEC signatures. The linking DS records in the TLD are presumably out of your control and in future can be audited through something like Certificate Transparency logs.

So even if you fully control the network path, you will somehow have to get access to my private key material.


Replies

akerl_today at 8:12 AM

The attacker did not fake any DNS records. They re-routed traffic to the legitimate IP addresses.

gzreadtoday at 4:08 AM

Solves part of it. They still control your HTTP and can make LE issue a certificate for you. So actually solves nothing.

Unless you had a CAA record saying only LE certs from your account are valid. And maybe you want that record to be authenticated.

show 1 reply