Remix.run Logo
akerl_ 3 hours ago

So why are we not constantly seeing real world compromises of major sites that don't use DNSSEC?

gzread 44 minutes ago | parent [-]

Here's one: https://notes.valdikss.org.ru/jabber.ru-mitm/

akerl_ 28 minutes ago | parent [-]

I don't see any indication that DNSSEC would have been relevant there? Their assessment was that that interception (and certificate issuance) were completed by redirecting traffic for the legitimate IPs to another destination. The DNS records continued to work as expected.