Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is nuts.

The only long term solution here is a distributed decentralized DNS service. When there's "default-trust" at some locations (browser CAs), There's weak-points in the security chain.

What are the best available dDNS solutions. Ideally these are initially backward compatible with redular DNS to help adoption, and then just disregard CAs.



Oh and browser vendors, distrust WoSign now!

Imagine your regular developer performing a npm install which pulls in code from a compromised MITMed github URL. That's straightforward rootkit compile and install access!


>Oh and browser vendors, distrust WoSign now!

It's not like a lot happened to other authorities (a few pinky-promises)



Some disagree that this is a good solution, e.g. https://news.ycombinator.com/item?id=12383795




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: