logoalt Hacker News

hugo1789today at 6:20 PM3 repliesview on HN

I think RPKI is good enough. As we have TLS on top it doesn't need to be perfect.


Replies

rot256today at 7:07 PM

For LetsEncrypt, routing is authentication: if packets routed to the IP in the A record end up at your place, you can get a cert for that domain.

maltalextoday at 6:35 PM

Only with certificate pinning or something similar. Otherwise, the attacker can get valid TLS certificates for any domain hosted on the hijacked IP addresses.

zymhantoday at 8:16 PM

Those two things address orthogonal issues