3 ms·
I think RPKI is good enough. As we have TLS on top it doesn't need to be perfect.
by hugo1789 6mo ago
I think RPKI is good enough. As we have TLS on top it doesn't need to be perfect.
- maltalex 6mo agoOnly with certificate pinning or something similar. Otherwise, the attacker can get valid TLS certificates for any domain hosted on the hijacked IP addresses.
- rot256 6mo agoFor LetsEncrypt, routing is authentication: if packets routed to the IP in the A record end up at your place, you can get a cert for that domain.
- zymhan 6mo agoThose two things address orthogonal issues