5 ms·
Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this
by ancarda 6y ago
Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different?
A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from
Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hosting and I think the domain was terminated
- jtdev 6y agoIt seems like we should be more focused on the possibility of this being abused rather than asking if it’s been abused yet.
- skynet-9000 6y agoIn this case, certificate revocation being so broken probably saved Parler from having it being done to them.
- superkuh 6y agoLet's put it another way. Do you think the Arab spring and Libyan civil war would've taken place if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? I don't. Now think of that on kind of thing happening with routes. Yikes. At least with the way things are now there's no ground truth. Every AS has it's own perception of the routing table and the ability to act on it. That's the way it should be. Securing BGP means less security because there is no global consensus even implied in the protocol. Securing BGP means centralizing BGP, not security.
- dane-pgp 6y ago> if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? But Gaddafi was already in control of all Libyan ISPs and the .ly ccTLD. Why would DNSSEC have made his job any easier? Also, surely Facebook was more instrumental in the Arab Spring than bit.ly was.[0] If anything, the lack of DNSSEC made it easier for Gaddafi to spoof DNS results for facebook.com and other sites. [0] https://en.wikipedia.org/wiki/Social_media_and_the_Arab_Spring https://en.wikipedia.org/wiki/Social_media_and_the_Arab_Spri...
- tptacek 6y agoGaddafi was not, to my knowledge, in control of any WebPKI CA=True certificates.
- dane-pgp 6y agoObviously for facebook.com he would only be able to serve an unencrypted HTTP version (and HSTS-preloading would prevent that working in most cases), but by controlling the .ly ccTLD he could acquire TLS certificates for any "national" site. I'm not sure if any of that is relevant, though.
- tialaramex 6y agoFor what it's worth this Gaddafi -> Libya -> bit.ly connection has to be one of the weirdest beliefs you've exhibited over a long period. At first I thought it was just an extended bit, like the whole Cody Johnston "teleporting boars" thing [0] But I don't think it can be, I think you're serious and er, that's not great basically. Maybe take a few minutes to think about it more clearly, discuss it with somebody you trust, and see if you can't figure out where you went wrong. [0] https://twitter.com/drmistercody/status/1046558632878399489 https://twitter.com/drmistercody/status/1046558632878399489
- superkuh 6y agoUm, okay. Who do you think I am?
- tialaramex 6y agoYou're superkuh, but I was replying to tptacek which is to say Thomas Ptacek, who has made this very strange argument multiple times.
- zaarn 6y agoAnyone can still accept routes that don't have the stamp of authority. I would also point out that the big authorities handing out the certification for this can also just revoke your IP block instead. You could still announce the block but since you're not longer in legitimate ownership of the IP block, it's likely that you'll quickly be blocked from announcing it.
- im3w1l 6y ago> Has this happened as HTTPS adoption has increased? This is such a naive way of looking at things. First a trap is built. Then you wait. Years. Only when the trap is filled to the brim does it snap shut. Many examples of that pattern.