Re: Registry lock - setting statuses on hosts

Marc Groeneweg <[email protected]> Wed, 16 Oct 2013 07:59:22 +0000
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
>> There is a scenario where you hijack the registrar, and change the
>> DNSSEC key material at the registry to DOS the victim. Or delete the
>> DNSSEC key material so you can do cache pollution.
>
>Having the private key at the domain holder would actually prevent that.

Is that true Jaap? I don't think so. The villain makes his own private key, and makes
sure he gets a real secure delegation to his own infrastructure, hijacking the domain
name and still have DNSSEC validation in place. I guess it's all about timing isn't it?

Regards,
Marc
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg