4 ms·
Was it at least private DNS?
by sunaurus 4y ago
Was it at least private DNS?
- teddyh 4y agoIn practice, there’s no such thing as “private” DNS. You can disable zone transfers and type “ANY” queries, but NSEC records of DNSSEC enable name enumeration, and public resolvers record and often publish the queries done through them. Do not put any private information in DNS. It’s not made for it, and many, many systems which work with DNS assume in their design that all DNS data is public.
- ericpauley 4y agoThey may be referring to private resolvers used within a private address range (e.g., https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/hosted-zones-private.html https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/ho...)
- teddyh 4y agoThe DNS data is still not encrypted over the wire, and clients could use their own local resolver which in turn uses the private resolver. This local resolver will most probably be designed with the assumption that DNS data is public.
- ericpauley 4y agoRoute53 private DNS is resolved over link-local addresses, so whether the responses are encrypted is irrelevant. They're specifically designed for private resolution within a VPC.
- teddyh 4y ago6. The network is secure. — https://en.wikipedia.org/wiki/Fallacies_of_distributed_computing https://en.wikipedia.org/wiki/Fallacies_of_distributed_compu...
- fiddlerwoaroof 4y agoThat’s assuming a generic network
- ericpauley 4y agoLink-local networking in VPC is specifically designed to secure data that is plaintext at the application layer (DNS). It’s effectively communication with the hypervisor, not over some untrusted link. If you don’t buy this, I guess you should start encrypting all your syscalls too?
- capableweb 4y ago> If you don’t buy this, I guess you should start encrypting all your syscalls too? Don't forget to encrypt all .socket's, and maybe encrypt everything over at /dev as well.
- waych 4y agoIf you believe a piece of link local infrastructure is a good carrier to trust your data, I have some great broken switches you may be interested in buying. Or if you insist on it being a virtual stack, how about some DMA engines with transient errors that mix up your packet headers from their payloads? The network is secure is a fallacy.
- ericpauley 4y agoThe “network” between the CPU and memory is also insecure. It’s turtles all the way down.
- HyperSane 4y agoYou could possibly encrypt them.