6 ms·
The local application would ensure that only .p2p DNS requests would get handled by this system. Presumably this would be open source, so you can verify yourse
by storborg 16y ago
The local application would ensure that only .p2p DNS requests would get handled by this system. Presumably this would be open source, so you can verify yourself that it's not going to intercept your bankofamerica.com requests.
Also, I think the intent is that any solution to this would include a cryptographic web of trust. However, it's probably still going to be the case that by visiting any .p2p site you are accepting risk--just as visiting many seedy torrents on an unpatched browser is risky now.
- eli 16y agoSo it'd be impossible to ever log in to an account at any .p2p site because at any point it may suddenly be in the control of an attacker? Seems rather limiting.
- burgerbrain 16y agoNothing would be preventing you from accessing the site with their regular domain name. This system is meant for when that isn't possible, for the vast majority of websites this is better than nothing. Obviously you should use discretion when using it, but that doesn't mean it isn't a good idea.
- wladimir 16y agoYou have to be careful. To be more sure you'd need another means to verify their authenticity (for example a SSL certificate). And preferably use a SSL certificate to authenticate yourself as well instead of a user/password pair. Sure, most websites still live in the 90's where it concerns security, but with P2P it suddenly starts to become much more important to have proper authentication for both sides :)
- eli 16y agoIt's not really a decentralized system if it relies on a central signing authority. I'm not sure what problem this solves.
- wladimir 16y agoSSH also checks public keys, without relying on any central signing authority. You could generalize this to SSL easily. You do need to be able to publicize your public key somehow with as little risk of MiTM as possible, but every secure communication method has this problem. Tor solves this by making a hash of the public key part of the URL. Of course, there might be more user-friendly solutions.
- storborg 16y agoIsn't that true of any non-SSL website now?
- eli 16y agoSure, except the surface area for a man in the middle attack has expanded from, roughly, someone on the same network as you to anyone anywhere on the Internet.
- jrockway 16y agoAlso, there is really nothing protecting "normal" DNS against spoofing right now. Sure, djbdns and the latest version of BIND are hard to attack (65536 source ports * 65536 transaction ids). But who knows what DNS software your ISP is using? Who knows how your Windows workstation handles forged responses? Incidentally, I think that if DNSSEC ever gets deployed, you'll be able to verify records even after they have been removed from the "real" DNS. That will solve both problems at once... but of course, the Internet always chooses workarounds in favor of clean solutions, so don't count on this happening any time soon. (My house has IPv6. But nothing else does...)