12 ms·
What do security folks think of the DNSSEC/DANE award? This isn't substantiated, but my understanding was that those technologies were considering kind of a jok
by Perceptes 10y ago
What do security folks think of the DNSSEC/DANE award? This isn't substantiated, but my understanding was that those technologies were considering kind of a joke by the security community.
- e12e 10y agoIsn't it more the case of them being a different joke than the CA system and cert pinning?
- viraptor 10y agoIt's "apply more of the same" compared to the CA system. Cert pinning is different, that part is controlled by the actual cert owner, but only starting on second connection.
- e12e 10y agoWell, "trust on first use without revocation" is an entirely special kind of broken key distribution. But then again, they are all broken.
- SEJeff 10y agoHere you go, now it is substantiated, by Thomas Ptacek, HN's very own "tptacek": http://sockpuppet.org/blog/2015/01/15/against-dnssec/ http://sockpuppet.org/blog/2015/01/15/against-dnssec/ His argument is pretty convincing if you read into it.
- tptacek 10y agoDNSSEC is considered a joke by a pretty broad chunk of the software security field. It's supported by people involved with the standard and by people who operate DNS infrastructure. Very few other people really understand it. It gets ambient support from a lot of netsec people who assume anything+SEC must be better than anything-SEC.