4 ms·
Yeah, password reset emails are sure a huge vulnerability. Nothing to do with DANE, though, since that won't solve that issue either (not going to spell out all
by PreInternet01 2y ago
Yeah, password reset emails are sure a huge vulnerability. Nothing to do with DANE, though, since that won't solve that issue either (not going to spell out all the reasons for that, but suffice to say that once a zone's registrar account is compromised, as with all examples so far here, the 'turn off DNSSEC' option is even deadlier than all other extremely practical attacks otherwise possible against the protocol...)