6 ms·
In SMTP, isn't it especially valuable to have DNSSEC for using DANE and not having to rely on the centralized web PKI?
by asimops 4y ago
In SMTP, isn't it especially valuable to have DNSSEC for using DANE and not having to rely on the centralized web PKI?
- pornel 4y agoDANE adds even more dependence on the even more centralized TLD owners, all eggs in their basket.
- dane-pgp 4y agoYou're missing the key difference: with the web PKI model, you have to trust every CA not to maliciously issue an unwanted certificate for your domain, whereas with DNSSEC, the owners of .ru (for example) can't affect your domain if it's under the .us TLD.
- tptacek 4y agoAnd you're missing the fact that CAs that misissue certificates can and will be distrusted by Chrome and Mozilla, but there's no way to revoke .COM.
- wizeman 4y ago> And you're missing the fact that CAs that misissue certificates can and will be distrusted by Chrome and Mozilla That doesn't protect against attacks from occurring, it only protects against future attacks from the same people who already attacked (assuming the same people don't create a new CA?). And when Chrome and Mozilla distrusts a new CA, good luck on updating the certificate chains included in the operating systems of all the devices in the world, especially those that never update (old Android phones? IoT devices?). > there's no way to revoke .COM I think there is no need to revoke .COM because .COM can attack any domain within .COM anyway, even with/without DNSSEC and/or with/without CAs? Or what am I missing?
- growse 4y ago> > there's no way to revoke .COM > I think there is no need to revoke .COM because .COM can attack any domain within .COM anyway, even with/without DNSSEC and/or with/without CAs? Or what am I missing? The point is you don't build a system that assumes DNS is trustworthy, because it isn't.
- wizeman 4y ago> The point is you don't build a system that assumes DNS is trustworthy, because it isn't. But the current CA PKI system already assumes DNS is trustworthy, even much more than if you were using DNSSEC-protected DNS PKI system, since it is not only vulnerable to almost all the same attackers/attacks, but it is also vulnerable to many more attackers (since any CA can also do an attack at any time, regardless of any possible future consequences it may experience or not).
- tptacek 4y agoNo, it doesn't.
- ThePowerOfFuet 4y ago> And you're missing the fact that CAs that misissue certificates can and will be distrusted by Chrome and Mozilla, but there's no way to revoke .COM. If they are caught — and CT has made that very likely, but hijinks like in Kazakhstan sidestep CT.
- tptacek 4y agoThat's an argument that cuts against DNSSEC, not for it. There's no transparency in the DNS PKI at all.
- wizeman 4y agoThere's no reason why you couldn't use certificate transparency with DNS PKI? Why do you seem to always be talking like if DNSSEC is incompatible with other security technologies? DNSSEC isn't incompatible with DoH either, but you also seem to be implying that we need to only use one or the other?
- tptacek 4y agoBy all means, do show me the crt.sh equivalent for DNSSEC. Easy way to win this leg of the argument!
- wizeman 4y agoI'm not saying it exists right now, I'm saying it could be created for a DNS PKI system if it was found to be necessary (like you seem to be implying)?
- tptacek 4y agoWill it have blackjack, and hookers? :) I'm not trying to be a jerk, I'm just saying, this thing you're talking about doesn't exist. Moreover: it's unlikely ever to exist. CT didn't get rolled out because the CA's wanted CT; I assume they actively detest it (other than LetsEncrypt). CT got rolled out because the browsers required it. The browsers have no leverage to make the DNS PKI do anything, because, once again, they can't revoke .COM.
- AndyMcConachie 4y agoCT is a joke. Trusting CAs to post all their certs to CT is a non-starter for me. A CA can issue a cert to the NSA and no one would know it.
- tptacek 4y agoThat works until a browser notices the misissued certificate, and then Mozilla removes the CA from their root program.
- wizeman 4y ago... which only works for browsers. What about all the other uses of certificates? TLS itself is used for securing almost every network communication that goes over the Internet nowadays, including SMTP (and even DNS with DNS-over-TLS or DoH, ironically). So how does Mozilla notice that a CA misissued a certificate for my SMTP server or my upstream DNS server? (Answer: it doesn't).
- tptacek 4y agoYour SMTP server can check SCTs the same way a browser can, but we're not talking about SMTP here.
- wizeman 4y agoWhat do you mean, more dependence? How does DANE make a domain more dependent on the TLD owners than they already are? Specifically, what kind of attack would a TLD owner be able to perform on a domain that uses DANE that they wouldn't be able to perform if the domain weren't using DANE?