|
|
|
|
|
by cmeacham98
422 days ago
|
|
With your solution, we end up with the same problem just one layer down. Browsers have to contain a list of 'trusted' registars, and an attacker only needs to find one buggy registrar that will incorrectly sign for a domain the attacker doesn't own. |
|
Basic math shows how much safer the new model would be:
So 4.75x fewer possible attack vectors.Add to this that with only 1 validation method and 1 feature to support, that's way less code, which means much fewer bugs.
Add to that a cryptographic chain of proof that the key of the domain owner was used to sign the request all the way, which we don't have today.