Elektrine lite

← Feed

@karlauerbach@sfba.social

Post #3967598

2026-07-20 18:05 UTC

@tychotithonus@infosec.exchange I have trouble accepting anything rooted in a country code top level domain (ccTLD), such as .me or .it, as being secure for use identifying people in the US. ccTLD domains are effectively controllable by the political forces in the country they represent. Some countries have delegated operation of their ccTLD to private operators. (ccTLDs are run, to the main, reasonably well. I am speaking here of possibilities not necessarily present realities.) Because DNS queries typically contain the entire set of DNS labels, it is possible for a ccTLD operator to capture nearly all queries to that ccTLD (by setting very short TTL values) and feeding controlled (or manipulated) answers (even with DNSSEC enabled.) I wrote a bit about this twenty years ago, but more about root servers than ccTLD servers. "What Could You Do With Your Own Root Server?" https://www.cavebear.com/old_cbblog/000232.html

Replies (1)