Hacker News new | ask | show | jobs
by mwwaters 985 days ago
I think the DNS key is only for the handshake to provide the certificate for the actual key. Without a certificate from a CA for second part, all the spoofed DNS key would get is what website they were trying to visit.