3 ms·
You do realise that the argument that that site is presenting is false. Firstly: "With TLS properly configured, DNSSEC adds nothing." DNSSEC presents you with
by wildfire 10y ago
You do realise that the argument that that site is presenting is false.
Firstly: "With TLS properly configured, DNSSEC adds nothing."
DNSSEC presents you with a valid, secure chain to know that the meta-data (encoded as TLSA) about the end-point you intend to communicate with is valid.
i.e. Grab the TLSA record for a hostname, validate the hostname (and TLSA record) via DNSSEC and then if the TLS certificate matches the details in the TLSA record you have confirmation that things are valid.
Secondly: "Securing DNS lookups isn’t a high-priority".
Then why there is a whole IETF WG dedicated to addressing it: https://datatracker.ietf.org/wg/dprive/about/ https://datatracker.ietf.org/wg/dprive/about/
Thirdly: "The real threat to CAs is “the global adversary”
i.e. organisations like the NSA, GCHQ collating everything, everywhere.
Any reasonable person could spend an afternoon - not being paid - providing a counterpoint to each item raised. None of them are (currently) relevant and the only one that is/was is actually being address in the IETF working group linked above.
- tptacek 10y agoThere's nothing in this comment that rebuts anything in "that site". Essentially, all you've managed to come up with is "it's wrong, because DNSSEC does what it does". I agree: DNSSEC does do what it does do. The problem is that what it does do isn't meaningful and doesn't add real security. At the same time, DANE/TLSA does create a system in which we replace certificate authorities with an organization run by the US Government.