4 ms·
If the network’s owner was the one doing DNS redirects, couldn’t they just instead use the IP address in the DNSSEC-signed record themselves? I don’t think DNSS
by tdtd 2y ago
If the network’s owner was the one doing DNS redirects, couldn’t they just instead use the IP address in the DNSSEC-signed record themselves? I don’t think DNSSEC is a robust protection if you don’t trust the network you’re connected to.
- lmz 2y agoThis would break the chain of trust (you wouldn't trust the network's key signing the address for that zone).
- tdtd 2y agoThe attacker doesn’t resign the DNS record with their own key, they just let the legitimately signed record though and use the IP address in that legitimate record themselves. If someone owns the network (or is an active MitM) they can control where IP addresses route to.
- tptacek 2y agoThey don't even have to do that. If they control the network, they can just set the AD flag to 'true' in a forged DNS response.