Hacker News new | ask | show | jobs
by pmilot 3773 days ago
Is it just me or the idea of trusting a random IP as your authoritative DNS server sounds like a phenomenally bad idea in terms of security? At least, when you pay for a service like UnblockUS, there's a contract and a certain understanding of accountability, which you don't have here...
3 comments

FBI: "We're going dark! What can we do?!" NSA: "Leave it to us."

Soon... "Point your DNS to us to unblock webvids non-Americans!"

I guess it can't hurt if you only use it to resolve Netflix.com, as long as you enforce HTTPS.
Oh yes it can. Ever heard of incompetent CAs loosing their private keys and signing rouge certificates?
The words you are looking for are "losing" and "rogue."
I don't know - perhaps loose certificates have a strong correlation with the amount of rouge ;)
Just use it on a "safe" device like a PS3 or something...
Agreed, it'd be worth trying with a set-top box of some variety where almost no data of consequence is being shared other than the aforementioned services but I'd be too wary of phishing for anything other than the most minimal of usage.