3 ms·
> You can potentially BGP hijack a domain (via DNS) domains and BGP don't really interact, can you explain what you mean?
by elktea 6y ago
> You can potentially BGP hijack a domain (via DNS)
domains and BGP don't really interact, can you explain what you mean?
- baybal2 6y agoI guess he meant the ip address
- tialaramex 6y agoI imagine what they're getting at is, you do a BGP hijack so that you get all the DNS queries about domain.example. So when a resolver asks about something.domain.example it gets told to ask servers authoritative for domain.example and it is given the IP addresses for some of those servers, but a BGP hijack could (if successful) allow you to answer for those IP addresses instead. At this point you can give any answers you like for such queries. If the domain has DNSSEC, you either have to choose answers you've seen that may be misleading (e.g. old but still not expired answers) or some resolvers might notice your answers are bogus. Many domains today don't have DNSSEC, so, you could give any answer and it will be indistinguishable from an answer by the legitimate authoritative DNS servers. Nobody would know any different. Now that you can cause traffic to go wherever you want, you can easily satisfy most of the Ten Blessed Methods and get yourself certificates in the Web PKI ("SSL Certificates") or whatever else you needed to achieve. In the distant future sometimes it may be possible that a recursive is able to assure itself that the answer is genuine via DPRIVE [DNS over HTTPS, or TLS, or QUIC or whatever else is invented] instead but in practice most of the routes by which we could get genuine answers ultimately rely on DNSSEC (DPRIVE is still doing something useful for you - privacy benefits, particularly oblivious transfer could mean you get trustworthy answers with a promise that your honest broker doesn't know what you asked, and the authoritative servers know what was asked but not who asked it)