4 ms·
They can not, the same way Lets Encrypt can not decrypt your private communications.
by ko27 4y ago
They can not, the same way Lets Encrypt can not decrypt your private communications.
- vorpalhex 4y agoActually LE could. They would re-issue a new valid cert for your domain without removing the old one. That would enable a MITM attack.
- geocar 4y agoOne could either spam DNS responses at the LE clients or push bogus BGP routes towards LE, and quite probably other things. And you don’t even need LE’s help to do any of this.
- lathiat 4y agoWhile these kinds of attacks are certainly possible, Let's Encrypt is not blind to them and has mitigations specifically for BGP hijacking for example: https://letsencrypt.org/2020/02/19/multi-perspective-validation.html https://letsencrypt.org/2020/02/19/multi-perspective-validat...