Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
c4mpute
on Oct 30, 2023
|
parent
|
context
|
favorite
| on:
Finding services companies via their TXT records
You could use your DNSSEC signing key to sign a validation message (offline, because that doesn't work over DNS).
agwa
on Oct 30, 2023
|
next
[–]
As discussed elsewhere in this thread, domain validation needs to be frequently rechecked. Therefore, it's far more convenient to publish a DNS record than to manually sign messages out-of-band.
remram
on Oct 30, 2023
|
prev
[–]
DNSSEC already provides attestation, why add another layer within the same system?
c4mpute
on Oct 31, 2023
|
parent
[–]
Because a DNSSEC attestation is usually public, except if you maybe use NSEC 3 and hide the RR behind some random name.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: