CAA record would only help in remaining TTL. Once expired, then it doesn't matter.
So yeah, these seem like decent steps to help protect but certainly not going to 100% prevent an attack like this one.
CAA record would only help in remaining TTL. Once expired, then it doesn't matter.
So yeah, these seem like decent steps to help protect but certainly not going to 100% prevent an attack like this one.
Actually it would have! Chrome and possible other browsers do not allow clicking throw certificate validation issues on sites with HSTS. For example, try to get to https://badssl.finn.io in Chrome.
Makes sense because it keeps HSTS from the lockout scenario that makes HPKP so scary.
There is no strong defense against this as a website. With an app the solution would be certificate pinning. You could try HPKP but that comes with a host of issues and I think it is being deprecated.
I think unless a TLD registrar gets hijacked that mitigates the attack on your own DNS after the NS TTL
Here though, people using area53 for DNS probably can't move away from it as they are stuck on amazon.
curl -I https://www.myetherwallet.com/
strict-transport-security: max-age=63072000; includeSubdomains; preloadBut MEW doesn't have HSTS? I would never use it personally on a public Wifi, but many people will for sure and they have no idea they'd be MITM'd.
Even without HSTS a bad actor would have to either trick a user to install a root cert or trick a certificate authority to generate a cert for the domain. Both of these are possible and have happened in the past, but they're also are a requirement for the attack you mention that you seemed to have completely forgotten about.
Are you thinking of HPKP?
Now I need to re-read the whole thread with this context. Thanks for the correction!