4 ms·
Ah hello 2015, my old friend. DNSSEC is a Government-Controlled PKI -> Not if the root of trust is secured by a proof-of-work blockchain DNSSEC is Cryptograph
by pinhead26 6y ago
Ah hello 2015, my old friend.
DNSSEC is a Government-Controlled PKI
-> Not if the root of trust is secured by a proof-of-work blockchain
DNSSEC is Cryptographically Weak
-> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605 https://tools.ietf.org/html/rfc6605
DNSSEC is Unsafe
-> NSEC3 is mentioned by the article itself
DNSSEC is Expensive To Deploy
-> We can make tools for this, so much has gotten easier already
DNSSEC is Incomplete
-> Agreed, we need browser adoption
- CiPHPerCoder 6y ago> Not if the root of trust is secured by a proof-of-work blockchain https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoculture https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoc... https://paragonie.com/blog/2017/07/chronicle-will-make-you-question-need-for-blockchain-technology https://paragonie.com/blog/2017/07/chronicle-will-make-you-q... > Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605 https://tools.ietf.org/html/rfc6605 First: That's a big "if". Lots of RSA legacy support. Furthermore, ECDSA is so bad that Ed25519 and Ed448 are even coming to FIPS 186-5 later this year. Citing ECDSA adoption in DNSSEC doesn't make as strong of a case as you might think.
- dane-pgp 6y agoFor context, some statistics: "Currently [2018], in more than 90% of cases if a user passes DNS queries to a resolver that performs DNSSEC validation of an RSA digital signature the same resolver will also perform DNSSEC validation of ECDSA P-256 digital signatures." https://blog.apnic.net/2018/08/23/measuring-ecdsa-in-dnssec-an-update/ https://blog.apnic.net/2018/08/23/measuring-ecdsa-in-dnssec-... "Since the second quarter of 2019 [to the first quarter of 2020], the population of [strict DNSSEC] validating users has risen from 12% to 22%, close to doubling. At the same time, the proportion of [non-strict DNSSEC validating] users has risen from 5% to 10%." https://blog.apnic.net/2020/03/02/dnssec-validation-revisited/ https://blog.apnic.net/2020/03/02/dnssec-validation-revisite...
- dane-pgp 6y agoA better argument against the preposterous claim that DNSSEC is "government-controlled" (and one that doesn't rely on blockchains, which are controversial in their own right), is that with DNSSEC you can choose which government (i.e. ccTLD) your domain is under, or choose one of the many generic TLDs. The web PKI, by contrast, requires users to trust a bunch of CAs, any one of which could have been compromised by a government and can issue a certificate for your domain. Also, if a government can compromise your DNS records, they can also be granted domain-validated certificates for those domains, so the web PKI is not an improvement. Anyway, if your threat model is that every single country in the world is willing to subvert the security of their own DNS hierarchy specifically to attack you, then the limitations of DNSSEC are the least of your worries.
- Avamander 6y agoWith the CT system I can monitor the CA's issuance, with DNSSEC I can't retroactively monitor if someone has changed the DANE keys and intercepted traffic.
- dane-pgp 6y agoTrue, DNSSEC Transparency is not as developed a technology as Certificate Transparency. There has been experimental deployment of such a system[0] but to give higher assurance there is a small addition to the DNS data that needs to be adopted first[1], which is still going through the IETF process. [0] https://twitter.com/ln4711/status/754516056878772224 https://twitter.com/ln4711/status/754516056878772224 [1] https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-delegation-only-00 https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-deleg...