Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
franga2000
5mo ago
0 comments
Share
Not tamper with the record directly, but MitM it on the way to a target.
0 comments
default
newest
oldest
ishouldbework
5mo ago
That should be prevented by dnssec no?
tptacek
5mo ago
Depends on who your adversary is. If it's your ISP: no, DNSSEC doesn't prevent that (in every mainstream deployment scenario, your upstream DNS recursive server is the only thing really doing DNSSEC validation).
crote
5mo ago
That's what DNSSEC is for.
franga2000
OP
5mo ago
Yes, but that's just PKI again, which is what the OP was trying to avoid.
j
/
k
navigate · click thread line to collapse