nanog mailing list archives
Re: This DNS over HTTP thing
From: "Valdis Klētnieks" <valdis.kletnieks () vt edu>
Date: Wed, 02 Oct 2019 05:45:57 -0400
On Wed, 02 Oct 2019 01:55:13 -0600, "Keith Medcalf" said:
It is a common fallacy that TLS connections are authenticated. The vast majority of them are not authenticated in any meaningful fashion and all that can be said about TLS is that it provides an encrypted connection between the two communicating applications. This is perhaps why it is call *transport* layer security ...
Another major disconnect is that TLS validates the hostname that the browser decided to connect to, not the host you thought you were connecting to.. The end result is that if a phish directs you to nan0g.org, it can still show a padlock and the user is none the wiser....
Attachment:
_bin
Description:
Current thread:
- Re: This DNS over HTTP thing, (continued)
- Re: This DNS over HTTP thing Jeroen Massar (Oct 01)
- Re: This DNS over HTTP thing Damian Menscher via NANOG (Oct 01)
- Re: This DNS over HTTP thing Niels Bakker (Oct 02)
- Re: This DNS over HTTP thing Tom Ivar Helbekkmo via NANOG (Oct 02)
- RE: This DNS over HTTP thing Keith Medcalf (Oct 02)
- RE: This DNS over HTTP thing Keith Medcalf (Oct 01)
- Re: This DNS over HTTP thing Jay R. Ashworth (Oct 01)
- Re: This DNS over HTTP thing Michael Thomas (Oct 01)
- Re: This DNS over HTTP thing David Conrad (Oct 01)
- RE: This DNS over HTTP thing Keith Medcalf (Oct 02)
- Re: This DNS over HTTP thing Valdis Klētnieks (Oct 02)
- Re: This DNS over HTTP thing Matt Palmer (Oct 02)
- Re: This DNS over HTTP thing Jan Philippi (Oct 02)
- RE: This DNS over HTTP thing Keith Medcalf (Oct 02)
- Re: FW: This DNS over HTTP thing bzs (Oct 03)