4 ms·
Firstly, MitM attacks on DNS: totally free. Nothing is authenticated, all is plain text in UDP. Just intercept packet and change the answer. Secondly, no, ther
by nmc 13y ago
Firstly, MitM attacks on DNS: totally free. Nothing is authenticated, all is plain text in UDP. Just intercept packet and change the answer.
Secondly, no, there is no third-part validation for DNS. There is better.
DNSSEC [1,2] takes advantage of the hierarchical nature of DNS to build a chain of trust. It does so by authenticating subdomain delegations, and signing resource records.
Keep in mind, even though all DNS root servers now do DNSSEC, Internet-wide deployment is still ongoing and coverage is far from satisfying.
[1] http://tools.ietf.org/html/rfc4033 http://tools.ietf.org/html/rfc4033
[2] http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions http://en.wikipedia.org/wiki/Domain_Name_System_Security_Ext...