Live data from Hacker News

So this guy is now S3. All of S3

chaos.social

461–470 of 522 posts

Re: So this guy is now S3. All of S3

#466

Earlier quoted context omitted.

> However that "somewhere" was just a location one of the devs at BlueSky chose, rather than somewhere relatively standardised, like under the ".well-known" path I've not looked into BlueSky's domain based identity thing in any detail so I might be missing a point somewhere, but… If someone can manipulate its special location what would there be to stop the same someone being able to manipulate content under .well-kn…

> Are we just relying on .well-known having some extra protection [...] ? If so then .well-known is little safer than any other arbitrary location in this respect. If .well-known had just been invented, that would be true. It's fairly well established at this point, though. For example, if someone can create arbitrary files in .well-known, they are also able to pass http-01 ACME challenges and thus issue TLS certs fo…

Good point with other common services like certificates via ACME.

Though MitM that way requires more steps than faking identity this way as you need to somehow get in the middle or redirect traffic towards you.

> I’d be much happier if proving domain control were only done through DNS challenges, but that ship has sailed.

Agreed.

Post reply on HN