7 ms·
Can somebody explain why this couldn't be as simple as adding a DNS TXT entry which says to use TLS for a specific domain? Then add a large TTL on this DNS entr
by zeroimpl 7y ago
Can somebody explain why this couldn't be as simple as adding a DNS TXT entry which says to use TLS for a specific domain? Then add a large TTL on this DNS entry so it can be cached for a week or more.
If it was that simple, I'd turn this on now.
- hannob 7y agoDNS is usually not secure. DNSSEC is not deployed widely. End of story.
- josteink 7y agoAll security of everything on the internet relies on DNS. If the problem is that DNS isn’t secure, nothing is, and DNS should be fixed first instead of fucking up every other internet protocol instead with crappy bandaids. That’s just obvious engineering. The people behind this spec are obviously incompetent or have ulterior motives.
- zeroimpl 7y agoYes, I don't see how this MTA-STS avoids the DNS security issue. The system first uses a DNS TXT record to indicate a policy exists, then uses HTTPS to fetch that policy.
- dcbadacd 7y agoWe have a standard for protecting DNS, but it's so bad - the tools are bad, the % of deployment is bad, the resolvers handle it bad, the ability for a regular sysadmin to deploy it is bad, it's just super bad compared to what we have with the HTTP PKI.
- tptacek 7y agoVirtually none of the security of the Internet depends on the security of the DNS; not depending on DNS for security has been an explicit design goal of Internet cryptography since the mid-1990s, which is, for instance, why IPSEC and DNSSEC evolved separately (DNSSEC was a DoD project spearheaded by TIS).