4 ms·
Very yes. `tptacek has great takes on DNSSEC
by CiPHPerCoder 7y ago
Very yes. `tptacek has great takes on DNSSEC
- wtallis 7y agotptacek has a tendency to deny the existence of problems that he doesn't consider to be important, and thus his criticism of DNSSEC tends to go a little bit too far. He does a great job of explaining what's wrong with DNSSEC and I agree with the general conclusion that it's not worth the trouble, but his blindspots are a bit annoying.
- tptacek 7y agoFeel free to provide an example!
- MertsA 7y agoNot OP, but in particular one of the major points of your post about the issues surrounding DNSSEC is that TLDs are controlled ultimately by the government with jurisdiction over them. Specifically I'm talking about the section titled "DNSSEC is a Government-Controlled PKI". You present the argument that the existing CA system is more protected from government interference than registrars. I think that argument is pretty weak considering that for the most part we're just talking about DV certificates and all a DV certificate from a CA signifies is that that particular CA verified that the entity they issued the certificate to controlled that domain. When ICE seizes a domain name, they can get a DV certificate no problem, they own the domain at that point. If Muammar Gaddafi ordered bit.ly to be seized for some hypothetical "Bureau of Information Technology", he could have absolutely gone to any CA afterwards and gotten a DV certificate. Why should a litany of CAs with authority to sign certificates for largely any TLD be preferable to only allow the entity that's authoritative on domain ownership being able to sign valid certificates? DV certs are just indirectly checking with DNS anyways and there are pitfalls in that process and no real benefits in the end.
- tptacek 7y agoGoogle and Mozilla can (and likely would) destroy the CA that allowed an unauthorized Gmail.com (not DNSSEC-signed, by the way) certificate to be issued. They have destroyed some of the largest commercial CAs in the industry for less. Neither Google nor Mozilla can revoke .COM, and the USG has repeatedly used its authority over .COM for public policy ends.
- MertsA 7y agoYet they haven't, and never will remove CAs that sign certificates for domains that ICE has seized. If the US government actually took the extraordinary step of just flat out taking ownership of gmail.com under the guise of some anti-trust action then they would meet the requirements to be issued a DV cert anyways. If the USG actually did seize control over gmail.com, and they had some CA sign a DV cert for them, how would that constitute a misissuance? The whole point of a DV certificate is that it only attests that the owner of the cert is the owner of the domain. The scenario we're talking about is a government becoming the new owners of a domain name. But regardless of that, mitigating government overreach by means of having hundreds of sacrificial CAs is a pretty poor solution. What happens if Let's Encrypt gets blacklisted? That's a huge chunk of the internet gone right there until everyone gets around to replacing them. IANA doesn't have to have the root and TLDs delegated to a single entity. DNSSEC could be replaced by something requiring signatures from multiple different entities in multiple different jurisdictions to actually solve this problem. Have the root and global TLDs signed by at least 3 out of 5 entities with no more than 2 of those being from a Five Eyes nation. IANA already has a mediation process to resolve disputes with domain names, there's no reason why legitimate domain seizures couldn't be subjected to that process rather than just a unilateral court order to the registrar. As for killing large existing CAs though, just look at how egregious Symantec was before Mozilla and Google ultimately decided to pull the plug. For years there'd be new ever more creative ways in which Symantec misissued certificates and their responses always seemed to be some variant of "Sorry, we didn't know we weren't supposed to issue certificates to entities other than the owner". There is still considerable friction to removing misbehaving CAs. As a matter of fact, Symantec in particular did misissue certificates for google.com back in 2015 during that whole test certificate debacle.
- wglb 7y agoWhat in particular are you referring to?