Post #2563465
2026-05-10 22:44 UTC
@dalias@hachyderm.io @ryanc@infosec.exchange @owen@mastodon.transneptune.net With the right tooling, even DNS-01 isn't the worst.
Replies (1)
-
@dalias@hachyderm.io 2026-05-10 23:11
@jima@mspsocial.net @ryanc@infosec.exchange @owen@mastodon.transneptune.net I just consider DNS-01 a giant weakness/violation of access controls. Automated processes should never have access to modify DNS, especially when that often (for non experts) means credentials to registrar.