4 ms·
Meanwhile DNS, which is a precursor to almost every connection ever, is rarely encrypted or authenticated in practice. Standards like DNSSEC and DNS over TLS ex
by packet_nerd 7y ago
Meanwhile DNS, which is a precursor to almost every connection ever, is rarely encrypted or authenticated in practice. Standards like DNSSEC and DNS over TLS exist but seem to have lots of vocal opposition without any serious proposals for improvement.
A Microsoft certificate training I took recently literally put emphasis on randomizing source port numbers as a way to mitigate attacks.... let that sink in.
- m_rn 7y agoPerhaps tls v1.3 will help? I've read cloudflare is doing major work to find dns solutions in conjunction with Mozilla encrypting sni, configuration for dnssec and so on. https://blog.cloudflare.com/encrypted-sni https://blog.cloudflare.com/encrypted-sni https://blog.cloudflare.com/encrypt-that-sni-firefox-edition https://blog.cloudflare.com/encrypt-that-sni-firefox-edition
- bennofs 7y agoWhat does encrypted/authenticated DNS gain you? If the application protocol is encrypted and authenticated like https then faking DNS responses just results in a connection that is closed immediately because authentication fails. Encrypting is also useless unless you use a proxy/VPN because otherwise the connection target leaks via the IP header anyway when you open the connection.
- packet_nerd 7y ago> What does encrypted/authenticated DNS gain you? Many things, here's three to start: * A measure of privacy - instead of every rando with ability to sniff packets (activities you have no way to ever know about, available to many parties along the path) only the DNS server (which you choose, presumably trust, and can change) knows what names you resolve. * Stronger foundation for TLS - LetsEncrypt and other public certificate authorities depend on DNS to issue certificates. If an attacker controls DNS, they could easily generate certificates for any site they wanted to attack. * There have been many shady incidents with certificate authorities. I just feel that beefing up some of the other layers in the stack is a good idea. > faking DNS responses just results in a connection that is closed immediately On the web it's often not closed immediately, the users often get a certificate warning that they may be conditioned to click through. Of course HSTS helps with that, but still... why the hostility to securing the name resolution layer?