4 ms·
Could DNS responses have been hijacked as well? Edit: Could this have been used to hijack/create TLS certificates?
by cangeroo 2y ago
Could DNS responses have been hijacked as well?
Edit: Could this have been used to hijack/create TLS certificates?
- kevindamm 2y agoDepends, do you have DNSSEC enabled?
- mort96 2y agoProbably not, I can't remember the last time I looked at 'resolvectl' output and saw anything other than "DNSSEC: no" on any system so I assume it mostly just doesn't exist in practice
- nightpool 2y agoMore practically: do you have DoH enabled? If you're using Chrome, the answer is probably yes.
- tptacek 2y agoDNSSEC doesn't help here. It doesn't run between stub resolvers and recursers like 1.1.1.1.
- georgyo 2y agoYes, unless you have some sort of protection. Protection could be validating DNSSEC (most likely not) Or using DoH (DNS over HTTPS) or DoT (DNS over TLS)
- terom 2y agoI don't think DNSSEC would help in the common case of non-validating stub resolvers querying a public resolver. My understanding is that the DNS query response from a DNSSEC-validating public recursive resolver doesn't contain the information required for the stub client to validate it, only a single AD bit.