5 ms·
Mandatory: https://moxie.org/blog/ssl-and-the-future-of-authenticity/ https://moxie.org/blog/ssl-and-the-future-of-authenticity/
by snakeanus 9y ago
Mandatory: https://moxie.org/blog/ssl-and-the-future-of-authenticity/ https://moxie.org/blog/ssl-and-the-future-of-authenticity/
- kuschku 9y agoAnd, in typical american fashion, 90% of the complains are specific to US users. If you use a TLD that is operated by a cooperative, such as .ee or .de, that entire problem is gone. You can even become member of them yourself, so anyone can become registrar — and you can switch in seconds to another if you need to. Trust agility is perfectly flexible with these models. Far better than with the CA model.
- icebraining 9y agoyou can switch in seconds to another if you need to. Who can, the site owner? Then you missed the point of trust agility as described by moxie.
- kuschku 9y agoThen moxie missed the point of how trust with websites works. You have to trust the site owner, who has to trust his hoster, his DNS provider, his domain registry. Transitively, you already trust all these people. DANE with DNSSEC does not add any requirement for new trust and it does not require that you trust any involved party more than before. It merely removes one entity from the equation.
- tptacek 9y agoNo, the owner of a site does not have to trust their DNS provider and registry. SSL and TLS were designed from the beginning to assume that the DNS was insecure --- they had to be, since the DNS was insecure when they were invented (and, of course, remains so today).
- kuschku 9y agoThat’s completely wrong. TLS today depends entirely on DNS – because anyone can receive a certificate for your domain if they control your DNS.
- icebraining 9y agoTreating trust as binary is folly. DANE means the provider could send the correct certificate to most people, but a fake one (along with a fake IP) to specific victims. Convergence distributes this verification, so the provider would have to give the same false result to everyone, otherwise a notary will catch the discrepancy.
- kuschku 9y agoAnd? The provider can request a lets encrypt certificate for the same domain already, and then give Let's Encrypt a wrong IP. This allows the same provider to get a fake certificate, and MitM only specific users. I don't see any additional attack surface.
- icebraining 9y agoYes, DANE is not necessarily worse than what we have right now. But what we have right now is what moxie is criticizing. His trust agility argument is for a new proposal (called Convergence), not to defend CAs vis-a-vis DANE.
- marcosdumay 9y ago> Treating trust as binary is folly. What? Any trust point being compromised would lead to the same result. Why would anyone use a non-binary comparison?
- icebraining 9y agoThat quote needs the context of the rest of the post to be understood. My point is that you can trust someone more if you increase the cost of violating your trust.