5 ms·
As long as DNS is insecure, Security Services can intercept and reroute IP addresses to send people to the security services version of the internet for brain w
by poiu345 8y ago
As long as DNS is insecure, Security Services can intercept and reroute IP addresses to send people to the security services version of the internet for brain washing. Installing a fake Certificate Authority on a computer through a zero day remote exploit or domain server hijack from a compromised router lulls users into thinking they are looking at genuine websites, but who knows what secure websites are signed by Digicert or some other CA? Just because its secure doesn't mean its not fake. IEEE standards are woefully inadequate and not joined up, but then one of the largest companies in the world namely Microsoft took 17years to roll out Address Space Layout Randomisation in Windows 10, coupled with Intel pursuing speed over security something which is mutually exclusive due to their chip designs, something ARM recognised a long time ago, so is it any surprise that the IEEE standards are where they are today? If you want to get a headups about what exploits are a problem get involved with the IEEE to find out what standards they are trying to improve to solve some hacking problem. The window of opportunity is open as long as the IEEE takes to finalize a standard.
In the mean time Happy Hardware Hacking because you know your existing security methods cant detect it, but your CPU fan may be the only indicator you have that some malware is running alongside your OS, in a QubesOS/Hypervisor style manner with a coreboot/libreboot bios gone rogue.
Prove me wrong!
- Leace 8y ago> As long as DNS is insecure, Security Services can intercept and reroute IP addresses (...) > (...) but who knows what secure websites are signed by Digicert or some other CA? Well, what would be that "secure DNS" in your opinion? If you assume someone can subvert Digicert would they be able to subvert that "secure DNS" too?
- skywhopper 8y agoFWIW, this is the attack that DNSSEC is meant to prevent.
- Leace 8y agoNot if "someone [who] can subvert Digicert" is government/state. In this case they have an easier task as governments directly control DNSSEC signing keys, and subverting Digicert and issuing rogue certs would be visible in Certificate Transparency logs.
- dane-pgp 8y agoGovernments directly control the DNSSEC signing keys for their ccTLDs, but at best indirectly control DNSSEC signing keys for some gTLDs. The US government could, for example, use some legal instrument to compel a US-based CA to issue a certificate for an arbitrary domain, and similarly compel a US company like Verisign (who manage the .com gTLD) to change the DNSSEC records for a .com address. The big differences are 1) you can choose a domain under a gTLD that isn't run by an American company (or other country that is part of your threat model), 2) you can choose to run your own gTLD (at a certain cost), 3) admittedly Certificate Transparency for CAs is much further along than CT for DNSSEC, you're right. https://tools.ietf.org/html/draft-zhang-trans-ct-dnssec-03 https://tools.ietf.org/html/draft-zhang-trans-ct-dnssec-03
- tptacek 8y agoI don't understand how people make this argument with a straight face. Google cannot simply abandon .COM. The most commercially important domains in the western world are all controlled by Five Eyes governments.
- dane-pgp 8y agoGoogle already do abandon .com for localised search in individual countries, and most people aren't actually typing "google.com" to find the search engine (it's probably a browser setting). Also, I don't understand how you can pick Google as an example with a straight face. The most commercially important websites in the western world are all run by companies that are controlled by Five Eyes governments.
- tptacek 8y ago