Domain Validation++ For MitM-Resilient PKI
Markus Brandt, Tianxiang Dai, Amit Klein, Haya Schulmann, Michael Waidner
Abstract
The security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a weak off-path attacker can effectively subvert the trustworthiness of popular commercially used CAs. Our attack targets CAs which use Domain Validation (DV) for authenticating domain ownership; collectively these CAs control 99% of the certificates market. The attack utilises DNS Cache poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. We discuss short and long term defences, but argue that they fall short of securing DV. To mitigate the threats we propose Domain Validation++ (DV++). DV++ replaces the need in cryptography through assumptions in distributed systems. While retaining the benefits of DV (automation, efficiency and low costs) DV++ is secure even against Man-in-the-Middle (MitM) attackers. Deployment of DV++ is simple and does not require changing the existing infrastructure nor systems of the CAs. We demonstrate security of DV++ under realistic assumptions and provide open source access to DV++ implementation.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 59b74c41-16d8-4ed5-9b29-bbdc57d45ae4Cited by top-tier papers28
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 33 citations
- Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNSPhilipp Jeitner, Haya SchulmannUSENIX Security 2021 · 32 citations
- Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)Amit KleinS&P 2021 · 26 citations
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker et al.USENIX Security 2021 · 23 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
Related papers
- ACME++: A Secure Authorization Mechanism for ACME Clients in the Web PKI EcosystemTianyu Zhang, Han Zhang, Yunze Wei, Yahui Li et al.WWW 2025
- ValidaTor: Domain Validation over TorJens Frieß, Haya Schulmann, Michael WaidnerNSDI 2025
- Let's Downgrade Let's EncryptTianxiang Dai, Haya Schulmann, Michael WaidnerCCS 2021 · 16 citations
- Good Cache, BAD Cache: Exploiting DNSSEC Validation Failures for DNS Cache Poisoning AttacksShiming Liu, Yunyi Zhang, Chaoyi Lu, Baojun Liu et al.CCS 2026
- From IP to transport and beyond: cross-layer attacks against applicationsTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerSIGCOMM 2021 · 14 citations
