Hacker News new | ask | show | jobs
by malaya_zemlya 1000 days ago
Coincidentally, the ACME DNS verification process that LetsEncrypt uses is vulnerable to the QUANTUM attack. If NSA injects a fake DNS response in the right spot, and have the their response arrive before the official response, they can get the domain verified.

OTOH, Certificate Transparency Logs will give the game away, so there's that.

1 comments

Doesn't Let's Encrypt check the DNS record from multiple widely-distributed endpoints to avoid this attack?