3 ms·
If they used DNS validation it would be better because there would be only one point of failure (DNS) rather than many (DNS and every ISP between CA and a site)
by codedokode 3y ago
If they used DNS validation it would be better because there would be only one point of failure (DNS) rather than many (DNS and every ISP between CA and a site).
- Jenda_ 3y agoThe thread above (https://news.ycombinator.com/item?id=37958831 https://news.ycombinator.com/item?id=37958831) elaborates on how to force DNS validation and/or how to tie your private key with Let's Encrypt via DNS.
- codedokode 3y agoEveryone needs to opt-in to use more secure methods and by default non-secure validation methods, which allow easy issuing fake certificates, are allowed. This is wrong.
- Jenda_ 3y agoSo, what should they do? No certificate without DNS record? Would this really help the overall state of affairs, or would most sites just not use HTTPS at all because it's "too complicated"?
- codedokode 3y agoThe purpose of using HTTPS is to make connections more secure. Giving away SSL certificates to anyone does not serve this purpose.
- lxgr 3y agoIt absolutely serves this purpose in a world in which there unfortunately is no TOFU/unauthenticated encryption for TLS (i.e. ours). Thanks to widely available HTTPS certificates, "evil hackers stealing your cookies on public Wi-Fi" is not a thing anymore. We should definitely have a discussion about whether it's made active attacks more feasible, but I think the goal of making passive sniffing less trivial than it was before can be considered achieved.
- lxgr 3y agoAnd DNS does not traverse several ISPs?