But without DNSSEC, is there any reason to trust the public key you get out of the DNS more than the key the host itself reports when neither is securely authenticated? Why can't an attacker who can pretend to be the remote host pretend to be the remote DNS server too?
no subject
Date: 2007-02-20 10:39 pm (UTC)