3 ms·
The difficulty is the comparative security posture. The HTTP-01 and DNS-01 challenges really don't require the web hosts to get their $h1t together to improve
by mdhardeman 9y ago
The difficulty is the comparative security posture.
The HTTP-01 and DNS-01 challenges really don't require the web hosts to get their $h1t together to improve security. (Technically, HTTP-01 could for some attack scenarios, but that would still be more difficult than this TLS-SNI-01 attack.) The TLS-SNI-01 mechanism does. Maybe it's the method that's deficient, rather than the web host.
(In truth both are, but one of those can be fixed timely, albeit with a bullet.)