logoalt Hacker News

akovaskitoday at 4:07 AM1 replyview on HN

I'm not sure what that would solve. You would still need some central entity to sign the DNS TXT record, to ensure that the HTTPS client does not use a tampered DNS TXT record.


Replies

tzstoday at 4:35 AM

If someone can tamper with your DNS TXT records now they can get a certificate for your domain.