Skip to Content [alt-c]

Comment

In reply to Comment by Reader Eivind

Andrew Ayer on 2015-12-04 at 15:49:

More powerful attackers can certainly respond with fake DNS replies and obtain certificates for any domain they like. This is a flaw inherent to all domain validation (DV) certificates. The solution is a combination of certificate transparency and public key pinning so that misissued certificates can detected and blocked.

But this blog post was about an attack which anyone on the Internet could have conducted, not just NSA-level adversaries.

Reply

Post a Reply

Your comment will be public. If you would like to contact me privately, please email me. Please keep your comment on-topic, polite, and comprehensible.

(Optional; will be published)

(Optional; will not be published)

(Optional; will be published)

  • Blank lines separate paragraphs.
  • Lines starting with ">" are indented as block quotes.
  • Lines starting with two spaces are reproduced verbatim.
  • Text surrounded by *asterisks* is italicized.
  • Text surrounded by `back ticks` is monospaced.
  • URLs are turned into links.
  • Use the Preview button to check your formatting.