3 ms·
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=tptacek%20dnssec&sort=byPopularity&type=comment https://hn.algolia.com/?dateRange=all&page=0&pref
by wolf550e 5y ago
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=tptacek%20dnssec&sort=byPopularity&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- egberts1 5y agoDNSSEC only protects their records which includes the mapping of domain name to IP address (and vice versa), nothing else. But why bother when web browser don’t even use DNSSEC itself? Because you can still send data securely under BGP hijack between your two endpoints with using DNSSEC-protected CAA record and a properly-CA-verified mutual TLS (mTLS).