logoalt Hacker News

dsr_today at 2:11 PM1 replyview on HN

If you can inject arbitrary malicious routes, you can make ACME requests for a new cert.


Replies

ThomasGlanzmanntoday at 6:47 PM

You can mitigate this with DNSSEC, CAA records and account pinning. See: https://www.devever.net/~hl/xmpp-incident