|
|
|
|
|
by tptacek
4163 days ago
|
|
Whether or not DNSSEC is ever seriously deployed, downgrade attacks against HTTPS will remain viable. It's easy to see one reason why this is true (DNSSEC only protects the DNS lookup and not the HTTP traffic itself), but there are other downgrade attacks as well. Downgrades are hard to protect against. Since DNSSEC can't decisively fix HTTPS downgrade, why bother deploying it? I addressed your ECC point in the followup to my post: http://sockpuppet.org/stuff/dnssec-qa.html Adam Langley seems to agree; he said "it won't happen within 10 years". |
|