4 ms·
I don't. Authentication is a pain, and the later in the stack you try to solve it the harder and hackier it gets. We have the gross hack of certificate authorit
by rictic 6y ago
I don't. Authentication is a pain, and the later in the stack you try to solve it the harder and hackier it gets. We have the gross hack of certificate authorities because we failed to deliver authenticated information via the domain name system.
> their host caches for that domain
Hm, would this trip a MITM flag if someone switched hosting providers? Like, if example.com is http only and is moved to a new datacenter, is there a way to distinguish this from someone MITMing the traffic?
- cookiengineer 6y agoAs of now, a change of server ips would trigger an MITM warning if the new server is still served via http. If it's https and has identical hash content values, it is currently assumed to be the same server. I basically decided to do this equivalent of statistical certificate pinning because I have no better solution at hand. I mean, you could have a couple of servers hosted in different geolocations and assume that if they crawl it and it's identical, then it must be true...but usually state level actors block it in the originating country, so it's hard to trace without something like a censorship index by geolocation (which is my plan for now). But honestly, I have no way to know whether this will work out, because every piece of the internet's infrastructure can be potentially infiltrated. I mean, that is ethernet by design.