Remix.run Logo
immibis 3 days ago

Makes it trivial for your DNS provider to MITM you, and you can't even use certificate transparency to detect it.

grishka 2 days ago | parent [-]

You can use multiple DNS providers at once to catch that situation. You can have some sort of signing scheme where each authoritative server would sign something in turn to establish a chain of trust up to the root servers. You can use encrypted DNS, even if it is relying on traditional TLS certificates, but it can also use something different for identity verification, like having you use a config file with the public key embedded in it, or a QR code, instead of just an address.