• db2@lemmy.one
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 year ago

    This brings a disturbing thought to mind… if an instance domain name like foo.bar lapses and someone else snaps the domain up (or of it gets stolen) can the new controller plop Lemmy on a server and be instantly federated? If so what kind of damage could they do?

    • lolcatnip@reddthat.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      This is why you don’t let your domain registration lapse. It’s not the only way computers on the internet verify each other’s identity, but a hell of a lot of internet security features are based around domain names, so keeping yours functioning is a very big deal.

      • finn@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Domain registration ≠ internet security. Root of trust is in cryptographic keys, not domains. DNS is not the security cornerstone you make it out to be. PKI says hi!

        • mle@feddit.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 year ago

          Yes, but it is very quick and cheap to get a domain validated cert from a CA that is generally trusted by most web browsers, so once the bad actor has the domain, the should be able to trick most users, only maybe certificate pinning might help, but that is not widely used.