3 ms·
I also considered using a DNS resource record (like SPF and DKIM), but HTTPS is more secure. What is the reasoning behind this statement? Resolving the hostnam
by jackalope 13y ago
I also considered using a DNS resource record (like SPF and DKIM), but HTTPS is more secure.
What is the reasoning behind this statement? Resolving the hostname for the HTTPS site still requires DNS. Is it because DNS isn't encrypted, so a MITM could change the POST URL? That's an issue with unencrypted HTTP, also, so you couldn't safely send this header on non-SSL pages. You'd need a login link that goes to an SSL-protected page first, in which case this just adds an extra (no longer useful) step.
- kijin 13y agoYes, I was referring to the fact that DNS responses are trivial to spoof. HTTP isn't much better, either, but at least an HTTP website can be turned into an HTTPS website without too much hassle. DNS on the other hand looks as if it will be stuck in its current form for many years to come. With HTTP(S), you can choose to be secure. With DNS, you're insecure and you have no choice.