Y
Hacker News
new
|
ask
|
show
|
jobs
by
roblabla
1181 days ago
DNS can
trivially
be mitm'd. DNS-stored fingerprints are strictly less secure than TOFU.
1 comments
tialaramex
1181 days ago
If you use DNSSEC (cue inevitable rant from Thomas) this just works. If you have DoH (and why wouldn't you?) and your trusted resolver uses DNSSEC (which popular ones do), you get the same benefits.
https://en.wikipedia.org/wiki/SSHFP_record
link
https://en.wikipedia.org/wiki/SSHFP_record