9 ms·
This is cool, but keep in mind that the operator can also get SSL certs for your site (they just point the domain somewhere else and use Lets Encrypt or similar
by robbya 7y ago
This is cool, but keep in mind that the operator can also get SSL certs for your site (they just point the domain somewhere else and use Lets Encrypt or similar to get a certificate). So from a security perspective, you are putting a ton of trust if you use this for anything real.
- anaphor 7y agoI don't think they even need to point the A record somewhere else. They can just create a TXT record and some CAs will allow you to validate it that way, if I'm not mistaken.
- joosters 7y agoPresumably they could just get a wildcard certificate for *.has-a.name perfectly legitimately and then they can mimic every IPv6 has-a.name site they want.
- milankragujevic 7y agoNot without the ability to add a TXT record to the root domain.
- joosters 7y agoWhich root domain? If they own has-a.name then that is good enough, right?
- LeonM 7y agoNo, they'd have to get a cert for your domain name. Which they can't, because they cannot prove they own your domain name. All they are doing if pointing to your IPv6 address, anyone can do that, that is why DNS TXT validation if needed in the first place.
- MrOxiMoron 7y agowhatever.has-a.name is the domain name they are suggesting you use, if you had your own you wouldn't need their service. So yes, you are basically giving them control that way. But for simple solution to temporarily get SSL to work on your container during development it's fine. But in that case a self signed certificate works too.
- LeonM 7y agoI haven't looked at it from that angle yet, but you are right: If you share the whatever.has-a.name address with other people and tell them to trust it, then this is very dangerous. However, the OP wrote this: > but keep in mind that the operator can also get SSL certs for your site Which made it sound as if they can get a cert for your domain, which they cannot.
- yzmtf2008 7y ago> Which made it sound as if they can get a cert for your domain, which they cannot. Why? They own and operate the DNS server for has-a.name, so (if they wish to) they can just add any record that they wish, to any domain, right? Of course this is true for any registrar, but that's also why not anyone can just become a registrar.
- ownagefool 7y agoObviously if you can sign a cert which is trusted by browsers, then you technically have the ability to impersonate anyone, but processes are used to fight against this. PSL (https://publicsuffix.org/ https://publicsuffix.org/), DNS Certification Authority Authorization , and Certificate Transparency could be combined so browsers are allowed to know who can sign what, who's a registrar, and who's doing what.
- yzmtf2008 7y agoPSL protects the other way around: it can only prevent whatever.has-a.name to compromise has-a.name or another.has-a.name DNS Certification Authority Authorization assumes trust of the DNS server. Doesn't work if the DNS server itself is compromised / malicious. (Maybe with DNSSEC, but DNSSEC has its own problems and definitely doesn't work when your TLD itself is compromised.) CT is really the only thing that works in this scenario (attackers/third party gaining write access to DNS records), but not every CA has CT and not everyone has the means to monitor CT logs. CT isn't even required for every browser/certificate (only EV certs (dead) for Chrome, and you need HPKP (dead) or Expect-CT (no browser support) for this to work reliably). Plus, what are you supposed to do when you find out there's a bad cert for your domain out there? Yell at someone on Twitter? It's going to be hard to convince a CA that you're not doing business with that someone with write access to DNS does not own the domain. Attackers are already impersonating you while it takes hours to sort things out. ... all of this is not to say that these security measures are bad, just not enough. We really put more trust on DNS servers than we ought to.
- milankragujevic 7y agoCan all the nice people who have downvoted explain what I said wrong?
- LeonM 7y agoAs far as I understand, all they are doing is resolving the ipv6 address in the domain name to an AAAA record that matches the IP address in the name. The domain name will still be 'has-a.name', so I don't understand how the certificate part is supposed to work. If anything you'd have to get their TLS cert for this to work, not the other way around.
- takeda 7y agoMaybe that's restriction for LetsEncrypt (I haven't used it myself) but certificates aren't restricted to 2nd level.
- LeonM 7y agoNo, this is nothing specific for Lets Encrypt, this is how PKI works. A certificate is for a domain name, not an IP address. Anyone can point a (sub)domain that they own to an IP address that they do not own. And then get a valid certificate for that domain. I can point an A record to [your-ip].[my-domain] and I will be able to get a valid cert for that address. However, the address in your address bar will still point to [my-domain], not yours.
- shawnz 7y agoYou can get a certificate for an IP address, but LetsEncrypt doesn't support it. So this might be somewhat specific for LetsEncrypt.
- djsumdog 7y agoI think the implication is if there is a security breech at their end, someone could hijack the service to point IPv6 addresses to somewhere unexpected. If it's only used in development, it's not too big a deal, but could still be use to compromise things.
- gregmac 7y agoAlso don't use for anything real, because you should not be teaching users that https://1234-5678-9adc-def0-1234-5678-9abc-def0.has-a.name https://1234-5678-9adc-def0-1234-5678-9abc-def0.has-a.name is the proper, trusted domain for your service. Because it was supposed to be https://1234-5678-9abc-def0-1234-5678-9abc-def0.has-a.name https://1234-5678-9abc-def0-1234-5678-9abc-def0.has-a.name and I just tricked you.
- numlock86 7y agoI actually had to look three times before I spotted it. Good one!
- Natfan 7y agoIn case anyone wants to know the difference it's that the third "section" on the first URL is "9adc" and the third "section" on the second URL is "9abc".
- TallGuyShort 7y agoI had to diff it! Even if there was no difference, the time it would've taken to be sure really illustrates the problem.
- treysis 7y agoSame/similar working mechanism is built-in into Windows since Vista: 1234-5678--abcd.ipv6-literal.net This doesn't even need functioning DNS and can work offline (add s<devnumber> for link-local addresses).
- jandrese 7y agoThe fundamental problem with this whole scheme is that it is still just trying to memorize the entire IP address. The point of a name is to make it something that feels natural for actual people. Maybe it would make more sense to choose the 65,536 most common English words (or whatever language you want) and break the address up into 8 words to form a crazy looking phrase. This is still difficult to memorize but not as bad as just stuffing 128 bits of hex down your throat. You could even allow for the collapsing 0s by making entry 0 be "and" and adding a bit of logic that does the collapse. For fun I wrote a tiny script that does this and tried it with their example domain: 1234:5678:9abc:def0:1234:5678:9abc:def0 -> balcony gaining pawn toothill balcony gaining pawn toothill Or Google's address from that page: 2a00:1450:4009:811::200e -> chinker bauchle dorter amor and bromidic So maybe this wasn't the best idea, but at least they're a bit more amusing than the hex noise in the article. Anyway, if anybody else wants to play around with it I have a tiny demo: http://jubei.ceyah.org/cgi-bin/ipv6toenglish http://jubei.ceyah.org/cgi-bin/ipv6toenglish
- stkdump 7y agoThe same amount of trust you put into any service managing domain names for you?
- perlgeek 7y agoUsually when you use a service to manage domain names for you, you have a contract with the managing party, which puts your relationship on much firmer legal grounds than when you use a random service provided for free and without legal guarantees.