Hacker News
new
past
comments
ask
show
jobs
points
by
hugo1789
3 hours ago
|
comments
by
rot256
2 hours ago
|
next
[-]
For LetsEncrypt, routing
is
authentication: if packets routed to the IP in the A record end up at your place, you can get a cert for that domain.
reply
by
maltalex
3 hours ago
|
prev
|
next
[-]
Only with certificate pinning or something similar. Otherwise, the attacker can get valid TLS certificates for any domain hosted on the hijacked IP addresses.
reply
by
zymhan
1 hours ago
|
prev
|
[-]
Those two things address orthogonal issues
reply