
6/18/2019 · Dina Kozlov, Gabbi Fisher
What this post added
This post introduces a new tool for Certificate Authorities (CAs) to enhance the security of Domain Control Validation (DCV) for certificate issuance. It details two primary BGP hijacking attack vectors (Sub-Prefix Attack and Equally-Specific-Prefix Attack) that can be used to obtain fraudulent certificates. It also discusses DNS spoofing as another method to compromise DCV. The proposed solution involves multipath domain control validation, ensuring that DCV requests are validated through multiple, independent network paths to mitigate the risks posed by network-level adversaries.