Y
Hacker News
new
|
ask
|
show
|
jobs
by
franga2000
198 days ago
Not tamper with the record directly, but MitM it on the way to a target.
2 comments
ishouldbework
198 days ago
That should be prevented by dnssec no?
link
tptacek
197 days ago
Depends on who your adversary is. If it's your ISP: no, DNSSEC doesn't prevent that (in every mainstream deployment scenario, your upstream DNS recursive server is the only thing really doing DNSSEC validation).
link
crote
198 days ago
That's what DNSSEC is for.
link
franga2000
198 days ago
Yes, but that's just PKI again, which is what the OP was trying to avoid.
link