3 ms·
If the DNS client has a pinned certificate/key this would break the MiTM/Middleware. But remember that you're only using the TLS connection for the DNS questio
by resonanttoe 8y ago
If the DNS client has a pinned certificate/key this would break the MiTM/Middleware.
But remember that you're only using the TLS connection for the DNS question and answer, so if you choose something like cloudflare/google/opendns then they'll configure their frontends/termination points with the respective pinned cert.
Once the lookup has taken place, the connection is made with the proper endpoint and a new TLS connection takes place using traditional mechanisms.
I feel that that most major providers have had enough of broken PKI infrastructure and bad uses that exposing DNS over TLS without something like Key pinning would be wise.
- badrabbit 8y agoIf you're pinning keys/certs,who needs a CA? If you don't need a CA,who needs the complicated TLS. I'd think wide adoption of TLS is the motivation,even then...DNS over QUIC? Either way,I'm all for it,just don't think the "end to end" label is warranted.
- move-on-by 8y agoJust a note, chrome is removing HPKP (public key pinning) validation. So this is unfortunately not true. I’m not going to go into the details here, but they basically believe it does more harm then good and that cert transparency logs achieve the same goal of taking away trust from the CAs.
- badrabbit 8y agoYeah,but now you're talking about browsers. You and others keep telling me how secure TLS and CA pki is,I never said otherwise. It's just not end to end. The subject here is dns over https and there certainly is no client auth here. TLS provides good transport security for the client. Not end to end,as in the CA infra for client auth isn't on par and even if it was CT is not TLS protocol feature and it's up to applications to verify CT,have only good root CAs and do client certs right