Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNS is not secured in any way (by default, DNSSEC is not that widely deployed yet and also not without flaws), therefore putting the fingerprint in DNS does nothing for protection against man-in-the-middle attacks.

DKIM is vulnerable against that, but the impact of doing so is lower (breaking anti-spam vs being able to intercept HTTPS)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: