None of these domain hijacking attempts would’ve been prevented by DNSSEC, right?
(Also kinda curious as to why pointing this out seems to be somewhat controversial? :)
(Also kinda curious as to why pointing this out seems to be somewhat controversial? :)
What would be better is to require 2FA for all zone hosting companies.
Even with this, many registrars and DNS hosts are too fast and loose with disabling 2FA when you call them up and tell them you lost your second factor. Alternatively, requesting changes over the phone without going through web authentication. My confidence in 2FA dipped quite a bit after going through the experience myself.
https://www.us-cert.gov/ncas/current-activity/2019/01/10/DNS...
https://news.ycombinator.com/newsguidelines.html
If you think you're seeing abuse, please email us with links (hn@ycombinator.com). That's in the rules too.