Hacker News new | ask | show | jobs
by franga2000 198 days ago
Not tamper with the record directly, but MitM it on the way to a target.
2 comments

That should be prevented by dnssec no?
Depends on who your adversary is. If it's your ISP: no, DNSSEC doesn't prevent that (in every mainstream deployment scenario, your upstream DNS recursive server is the only thing really doing DNSSEC validation).
That's what DNSSEC is for.
Yes, but that's just PKI again, which is what the OP was trying to avoid.