Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mittalprat
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
mittalprat
5y ago
Having a CAA record and pointing to a CA like Let's Encrypt that uses domain validation from multiple vantage points on the Internet is a useful idea and raises the bar for an adversary. I should point out that BGP attacks can also tar
2.
▲
by
mittalprat
5y ago
Indeed, your comment illustrates the importance of proactively strengthening the domain validation protocol used for issuing digital certificates. Our work with Let's Encrypt demonstrated the feasibility of validating domains from mult
3.
▲
by
mittalprat
5y ago
Indeed, a number of internet services and applications are vulnerable to BGP hijacking and interception attacks, including TLS/digital certificates, anonymity systems such as Tor, and cryptocurrencies such as Bitcoin. We discussed this
4.
▲
by
mittalprat
7y ago
For readers interested in understanding the technical details about potential BGP attacks on domain validation, which serve as a motivation for Let's Encrypt's multi-perspective validation deployment, see the following paper from
5.
▲
by
mittalprat
7y ago
Indeed, the self-signed cert idea doesn't work in this context.
6.
▲
by
mittalprat
7y ago
If the domain is hosted on a /24, then more specific routes will be filtered out by default in most ASes. Also, with the increasing adoption of RPKI, in conjunction with its maxlength option, more specific attacks will be a challenge f