4 ms·
Swedish regulation requires DNSSEC for government domains (MSBFS 2020:7 for the DevLegalOps nerds like me out there). I mostly agree with the author, except fo
by anticristi 3y ago
Swedish regulation requires DNSSEC for government domains (MSBFS 2020:7 for the DevLegalOps nerds like me out there).
I mostly agree with the author, except for one issue: ACME is currently vulnerable to DNS MitM attacks. LetsEncrypt reduces this risk by spreading validation across the globe, to decrease the likelihood of a successful DNS MitM. However, I feel that DNSSEC is the sound solution here.
- patrakov 3y agoThey are protecting against the wrong attack. MitM is mostly theoretical. An irresistable government order (supplemented with people holding guns) for the DNS provider to insert the "correct" _acme-challenge record is something real, and DNSSEC makes this attack impossible.
- peanut-walrus 3y agoThose same people with guns can also force your registrar to request removal of the DS record. Or in the case of ccTLDs, the people with guns might already control your TLD operator and can just answer the acme-challenges themselves.