5 ms·
What's better?
by rubyist5eva 4y ago
What's better?
- superkuh 4y agoIt's not about better. The internet is best served by having multiple options available, encrypted and clear text. When a CA based TLS service is the only option that means CAs control even more. And CAs fuck up, often, intentionally, unintentionally, and because of external pressures. The more people pile in one CA the more pressure. LetsEncrypt is great and I'm glad it exists, but everyone using it is bad for the internet's health.
- rubyist5eva 4y agoI agree with you about CAs but maybe "better" wasn't the right word and what I meant is, what are the current alternatives? The only ones I know about are DoT and DoH which are mostly interchangeable.
- spijdar 4y agoIs there really that significant of a difference between clear text and just accepting an arbitrary TLS cert without trusting a CA? I can understand criticizing the modern TLS/CA system if you're concerned about security, but how does clear text avoid the failings of "bad CAs" here? It's not like encrypting with a cert signed by a corrupt CA gives any entity the ability to do bad things, no more than would be possible over clear text, at least.
- superkuh 4y agoIn this context, as DNS over HTTPS, you're right. There's not much difference except that the provider has to only allow uses of it's DNS service that won't upset the CA TLS cert provider. And the user of DNS lookups has have a very modern computer (software-wise) to support the ever changing root certs; so using old, stable, software (and retro-computing) is further restricted. But it is much different in other contexts like HTTPS (HTTP/2 + HTTP/3) only browsers where now human people are unable to host a visitable website without getting a continued approval from a CA.
- googlryas 4y agoUDP DNS seems intrinsically broken due to address spoofing. Is there an unencrypted TCP DNS standard?
- GTP 4y agoYou can spoof also with TCP, don't you?
- yardstick 4y agoYes TCP DNS has been a thing since forever. All the main DNS providers support it. But as it’s unencrypted it’s still subject to MITM attacks.
- hathawsh 4y agoYes -- "DNS uses TCP when the size of the request or the response is greater than a single packet such as with responses that have many records or many IPv6 responses or most DNSSEC responses." [1] 1. https://serverfault.com/questions/404840/when-do-dns-queries-use-tcp-instead-of-udp https://serverfault.com/questions/404840/when-do-dns-queries...
- SahAssar 4y agoWould you be fine with it if it worked with DANE/TLSA? I agree that centralizing on CAs is not great, but I think encrypting DNS is in general a good thing.
- lxgr 4y ago> The internet is best served by having multiple options available, encrypted and clear text. > CAs fuck up Sure, but when a CA fucks up, the security of DoT isn't worse than that of plaintext DNS, is it? With ephemeral keys being ubiquitous in TLS, you even need an active MITM attack to degrade to plaintext; in the face of a passive eavesdropper, DoT using a completely compromised CA is still a vast improvement from a privacy point of view.
- jedisct1 4y agoDNSCrypt, especially with anonymization?