6 ms·
after reading the headline I immediately thought of "14 DNS Nerds Don't Control the Internet" [0]. [0] https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont
by fosco 8y ago
after reading the headline I immediately thought of "14 DNS Nerds Don't Control the Internet" [0].
[0] https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont-control-the-internet/ https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont-con...
- unethical_ban 8y agoWhat a strange article. I thought it was leading up to saying that control of DNSSEC is decentralized, or has a transparency process, or something. But instead of 14 nerds, it's the US government (for .com). I need to read up on DNSSEC.
- wav-part 8y agoMuch better than (CA0 || CA1 || ... ). All it takes is one CA out of 10s of independent CAs to misbehave to insecure whole tls. In DNSSEC/DANE, world only has to watch one entity rather than 10s of entities.
- akerl_ 8y agoExcept if that one entity misbehaves, even if you catch them, you can't do anything about it, because they own the TLD.
- wav-part 8y agoYou have to trust somone under DNS. The only trustless naming system I can think of is over a PoWChain (eg example.btc). Still you have 3 choices in DNSSEC/DANE, - get a .xxx, trust dnsroot. - get a .xxx (when .xxx is as easy to register as xxx.com), trust dnsroot. - pick one tld out 1000s and get xxx.ttt, and trust ttt and dnsroot.
- akerl_ 8y agoI’ve got those choices if I use DNSSEC for my trust, correct. Or I use the existing system, where if a CA misbehaves, we boot them out of the browser trust stores and site operators don’t have to change anything.
- wav-part 8y agoExcept there has to be a crypto proof why Google owns google.com not me. That means we need to secure dns. Then why need CAs at all ? Whats the point ?
- tptacek 8y agoA group of certifying singers that aren’t directly controlled by the United States Government is the obvious reason.
- wav-part 8y agoCurrent: Google need to watch all CAs. DNSSEC: Google need to watch .com and dnsroot. Which one is better ? ---- (I am ratelimited so posting here rather than reply to the child post by tptacek https://news.ycombinator.com/item?id=18889809 https://news.ycombinator.com/item?id=18889809) Of course they can. There is literally no legal or otherwise difference between Verisign and .com. Chrome can do whatever it want, cause its Google's browser not .com's. In case when .xxx becomes dishonest, you can just move to your own gtld or .more-trustable tld. In current system, there is no concept of ditching a CA. If a CA decided to missmap a name and you are too small, you are fked. > it’s actually 1, or 1 AND 2 No you can have DNSSEC without CAs. I have explained that already without changing much of the tls. Basically example.com DNSSEC key become CA for example.com. example.com then would create a tls cert in the usual way. No pain.
- topranks 8y agoYeah but because they own the TLD they can get X.509 certs issued for any domain under it, because controlling the domain is the only check CAs really perform before issuing a cert for a domain. The DNS is already acting as the root of trust for X.509. X.509 does not make the scenario of a rogue TLD operator any different.
- tptacek 8y agoNo. You have to trust all the CAs, and the governments that control the DNS. https://www.imperialviolet.org/2015/01/17/notdane.html https://www.imperialviolet.org/2015/01/17/notdane.html
- wav-part 8y ago> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority that clients need to map DNS . to existing root keys. A client can map a.b.c to any key it wants. The risk of gov overreach is same for both tls and DNSSEC. DNSSEC just trusts fewer entities. The only people who benefit from current system, are CAs who are getting $$$ for nothing. > https://www.imperialviolet.org/2015/01/17/notdane.html https://www.imperialviolet.org/2015/01/17/notdane.html This is orthogonal. Weak Keys are not required or implied characterstic of DNSSEC.
- akerl_ 8y agoIf browsers start mapping cert trust to something besides the DNS roots... it’s not DNSSEC, it’s something else entirely, it’s “our current system, maybe with some slight tweaks”
- wav-part 8y agoI am not suggesting every client do their own mapping, that is not a naming system at all. There has to be very large consenus for a naming system to be effective. I just pointed that out to show that dns is not under any gov control. Its under a control of an entity that can be punished. However who gets to have dnsroot is just a value of a config in DNSSEC. The value itself should not be used to criticize DNSSEC cause its changeable.
- akerl_ 8y ago
- topranks 8y agoThere are about 1500 entities in the X.509 game, not 10s.
- topranks 8y agoThat article is peddling bullshit. Yes, DNSSEC is not adopted. But what the intention with it is to stop people hijacking DNS requests (re-routing then to rogue servers for instance,) and then returning spurious answers. That’s a relatively simple attack, and it can have fairly serious reprocussions. Just return an A record for the domain and host straight HTTP for example. Or re-divert emails with MX records. Publish fake CAA records to bypass that safety lock if you want to supply a cert obtained elsewhere. The stuff about the US Govt controlling sites is the most facetious of all. As the original (non) story above shows, controlling the DNS is all you need to control a site in the X.509 world. Extended validation is a joke, controlling the domain is the only barrier to getting TLS certs issued for any domain. We implicitly need to trust the root DNS. That’s a given. So why couldn’t it be the root of trust for secure browsing? Browsers trust something like 1500 CAs out of the box these days, is it really better to create a system where that many orgs need to be honest, and not get hacked, to be effective? To claim that the current system, with no way to for people know the DNS answers they receive are valid, poses no security risk, is extremely foolish.
- tptacek 8y agoHere's a story about a DNS hijacking attack unprecedented in scale for which DNSSEC is powerless, and your conclusion is that DNSSEC is an important priority. If you believe control of the DNS is straightforward without DNSSEC, and that control of the DNS is all you need to get an X.509 certificate issued, go get a GOOGLE.COM certificate misissued. Or FACEBOOK.COM. If you actually manage to do it (you won't), turn the timer on your iPhone on so we can measure how long it takes for Google to kill the CA you got it from, with no notification or further intervention from you. We do not implicitly trust the DNS roots. In fact, it's a core feature of modern Internet security (modern since the late 1990s) that we do not trust DNS at all. It is a small faction of standards zealots, whose pet standard failed for almost 30 years to either gel or get traction in the market, who have decided that their spurned work turns out to be critical to all Internet security, and they're the ones revisiting that long-decided question. You made this argument in, I think, 3 other places in this thread, and I'd just like to say that I put some effort into making sure my rebuttals relied on different arguments each time. Collect them all! I wrote them I think a little snarkily, but I tried to exceed the bar you set by claiming I'm "peddling bullshit".