6 ms·
That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to
by caskance 11y ago
That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.
- tptacek 11y ago"DNSSEC: everything will be fine as long as everyone moves to domains in Bouvet Island's .BV. Brought to you by Cloudflare."
- drzaiusapelord 11y agoand exactly what country is safe from the whims of politics? I was just reading about censorship in the Netherlands and other Euro states because of fear of offending religious people, especially muslims. If the far left Europeans can't protect speech, then who can? DNNSEC just enables centralized government control on a level that's not needed. DNS is fine as-is. Domain authentication should be done via the transport layer like SSL. That's the way things are going now anyway.
- stephenr 11y agoSecure DNS allows a number of nice things that otherwise are a risk, such as trusting server SSH fingerprints without prompting on first use.
- tptacek 11y agoAnd to get that feature all you have to do is trust that the government that controls your TLD isn't going to fuck you. Because it's not like the USG would ever tamper with the DNS to further a policy goal, right? http://gizmodo.com/5936870/doj-seizes-domains-over-app-piracy-for-the-first-time-ever http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...
- throwaway2048 11y agoeven in the case of existing CA model+key pinning (at least before the key is pinned) you are still trusting the governments controlling the TLDs are not going to fuck you. Id rather trust a handful of cctld nation states, than the nation states + everybody with access to a CA cert. Also the idea that dnssec tld keys cannot be rotated is pure FUD, the root key signing keys themseves cannot, but they were extremely careful there. If tampering is detected, do you really think TLD keys are going to be left alone, and not regenerated and the process extremely closely scrutinized?
- caskance 11y agoThat's the trust that government always requires. Being on the internet doesn't change the fact that the point of government is a monopoly on authorized use of force. They can always just send men with guns to your office, DNSSEC or no. If you don't trust your government not to abuse their power, that's not a problem that Cloudflare can help you with.
- tptacek 11y agoWe're required to trust them for the DNS today. We aren't required to trust them for TLS keys. But DNSSEC/DANE formally and irrevocably gives them that authority.
- caskance 11y agoThey already have the ability. Since that can't be revoked, might as well make it transparent and grant them the authority to match it. It's certainly better than the current CA system.