|
|
|
|
|
by bhauer
3533 days ago
|
|
Kalium, I really appreciate your responses. If my adversary can steal an IP from Facebook, create a valid certificate for facebook.com, and provide bogus DNS resolution for facebook.com, I feel it's game over for me. My home network is forfeit to such an adversary. But I get your point. It's about layering on mitigating factors. The lower the TTL, the lower the exposure. Still, my current calculus is that the risk of being attacked by such an adversary is fairly low (well, I sure hope so), and I would personally like to configure my local caching resolver to hold onto last-known-good resolutions for a while. All that said, I have to hand it to you and others like you, those whom keep the needle balanced between security and convenience. |
|
Keeping the balance between security and convenience is difficult on the best of days. Today is not one of them. :/