5 ms·
> From my perspective, I believe that we should work on pushing for wider adoption of DNSSEC, because I continue to come back to the core problem of DNS results
by CiPHPerCoder 7y ago
> From my perspective, I believe that we should work on pushing for wider adoption of DNSSEC, because I continue to come back to the core problem of DNS results not being authenticated or verified.
Can we replace DNSSEC with something that doesn't give government control over root zones?
- jsiepkes 7y agoYou mean DANE? Chrome had that for a short while but then removed it.
- jsiepkes 7y agoSorry I'm confused; you need dnssec for Dane of course...
- cuillevel3 7y agoThis comes to mind: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- CiPHPerCoder 7y agoVery yes. `tptacek has great takes on DNSSEC
- wtallis 7y agotptacek has a tendency to deny the existence of problems that he doesn't consider to be important, and thus his criticism of DNSSEC tends to go a little bit too far. He does a great job of explaining what's wrong with DNSSEC and I agree with the general conclusion that it's not worth the trouble, but his blindspots are a bit annoying.
- tptacek 7y agoFeel free to provide an example!
- MertsA 7y agoNot OP, but in particular one of the major points of your post about the issues surrounding DNSSEC is that TLDs are controlled ultimately by the government with jurisdiction over them. Specifically I'm talking about the section titled "DNSSEC is a Government-Controlled PKI". You present the argument that the existing CA system is more protected from government interference than registrars. I think that argument is pretty weak considering that for the most part we're just talking about DV certificates and all a DV certificate from a CA signifies is that that particular CA verified that the entity they issued the certificate to controlled that domain. When ICE seizes a domain name, they can get a DV certificate no problem, they own the domain at that point. If Muammar Gaddafi ordered bit.ly to be seized for some hypothetical "Bureau of Information Technology", he could have absolutely gone to any CA afterwards and gotten a DV certificate. Why should a litany of CAs with authority to sign certificates for largely any TLD be preferable to only allow the entity that's authoritative on domain ownership being able to sign valid certificates? DV certs are just indirectly checking with DNS anyways and there are pitfalls in that process and no real benefits in the end.
- tptacek 7y agoGoogle and Mozilla can (and likely would) destroy the CA that allowed an unauthorized Gmail.com (not DNSSEC-signed, by the way) certificate to be issued. They have destroyed some of the largest commercial CAs in the industry for less. Neither Google nor Mozilla can revoke .COM, and the USG has repeatedly used its authority over .COM for public policy ends.
- MertsA 7y agoYet they haven't, and never will remove CAs that sign certificates for domains that ICE has seized. If the US government actually took the extraordinary step of just flat out taking ownership of gmail.com under the guise of some anti-trust action then they would meet the requirements to be issued a DV cert anyways. If the USG actually did seize control over gmail.com, and they had some CA sign a DV cert for them, how would that constitute a misissuance? The whole point of a DV certificate is that it only attests that the owner of the cert is the owner of the domain. The scenario we're talking about is a government becoming the new owners of a domain name. But regardless of that, mitigating government overreach by means of having hundreds of sacrificial CAs is a pretty poor solution. What happens if Let's Encrypt gets blacklisted? That's a huge chunk of the internet gone right there until everyone gets around to replacing them. IANA doesn't have to have the root and TLDs delegated to a single entity. DNSSEC could be replaced by something requiring signatures from multiple different entities in multiple different jurisdictions to actually solve this problem. Have the root and global TLDs signed by at least 3 out of 5 entities with no more than 2 of those being from a Five Eyes nation. IANA already has a mediation process to resolve disputes with domain names, there's no reason why legitimate domain seizures couldn't be subjected to that process rather than just a unilateral court order to the registrar. As for killing large existing CAs though, just look at how egregious Symantec was before Mozilla and Google ultimately decided to pull the plug. For years there'd be new ever more creative ways in which Symantec misissued certificates and their responses always seemed to be some variant of "Sorry, we didn't know we weren't supposed to issue certificates to entities other than the owner". There is still considerable friction to removing misbehaving CAs. As a matter of fact, Symantec in particular did misissue certificates for google.com back in 2015 during that whole test certificate debacle.
- techntoke 7y agoLike a blockchain-based DNS provider?
- cryptonector 7y agoI suppose you could have blockchain DNSes. Indeed, attempts have been made. Of course, then you get the same problems as with cryptographic coins, where getting 51% of mining resources lets you double-spend, which for DNS would mean letting you MITM specific targets. And guess what governments would do about that? Repeat after me: rubber hose cryptanalysis is unbeatable / cryptography cannot solve political problems.