logoalt Hacker News

buzeryesterday at 6:29 PM2 repliesview on HN

CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.tesla.com certificate though it might take quite a few tries.


Replies

robinpieyesterday at 6:33 PM

I thought about trying this, but MPIC makes it very very very difficult (the round-robin has some geolocation magic baked in regarding what server it connects you to).

show 1 reply
sippingabonedryyesterday at 6:44 PM

Wouldn't the same apply to pool.ntp.org then?

Maybe running a web server on the same IP as an NTP server is a bad idea.

show 1 reply