5 ms·
Having a CAA record and pointing to a CA like Let's Encrypt that uses domain validation from multiple vantage points on the Internet is a useful idea and raises
by mittalprat 5y ago
Having a CAA record and pointing to a CA like Let's Encrypt that uses domain validation from multiple vantage points on the Internet is a useful idea and raises the bar for an adversary.
I should point out that BGP attacks can also target the CAA records themselves since the DNS ecosystem is itself insecure. This is why such attacks are not easy to defend against, and require holistic improvements across internet routing, PKI, and web security practices.....
- egberts1 5y agoIt is only because the web browsers are still not doing DNSSEC-only query and validation, CAA can easily be spoofed right there. To avert a DNSSEC-secured DNS CAA record from being tampered under BGP hijack, both endpoints must deploy their own cacheless DNSSEC authoritative-only resolvers before commencing mTLS endpoint communication. (Like a web browser would even do that /s). This places the trust of DNSSEC to right at the 13 DNS Root Servers whose private key are stored in a HSM key vault. So, hijacking a DNS infrastructure to tamper the CAA record is only possible because 1) web browser don’t bother with DNSSEC 2) domain owner don’t bother with DNSSEC protection. But even with insecure DNS, I assert that a properly designed REST/HTTPS/“mTLS” API (but would then be totally unusable by web browsers) would still not be intercepted under BGP hijack scenario so that is still an option for any B2B scenario.