Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Malicious DNS can request cert for the domain via e.g. let's encrypt, then it can do whatever it wants.


My understanding is that it doesn't apply at least to EV certificates. Also, the parent says that "any user who is delegating their DNS lookups to a third party", but that can't apply to such users either.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: