4 ms·
TLS security is rooted in DNS. It's ACME DNS-01. If your threat model includes nation states, this is a non-solution
by matthew9219 3y ago
TLS security is rooted in DNS. It's ACME DNS-01. If your threat model includes nation states, this is a non-solution
- Avamander 3y agoIf your threat model includes nation-states then DNSSEC won't help you either. WebPKI at least has a method for keeping track of and detecting misissuance, DNSSEC doesn't.
- rakoo 3y agoWrong, TLS security is independent from DNS. If my threat model includes nation states I'll trust my own certificates or my very own CA.
- teddyh 3y agoBy trusting certificates, you implicitly trust all CAs, not just your own.
- rakoo 3y agoNo, again in that threat model I can decide exactly which certificates and which CA I trust, one by one.
- tptacek 3y agoYou trust your browser's root program, not "all CAs".
- teddyh 3y agoThat’s what a “CA” is. If someone is not in a browser’s CA list, they’re not a CA. So yes, you do trust all CAs.
- tptacek 3y agoNo, obviously, different TLS programs have different root programs.
- acdha 3y agoThat’s not all what CA means in standard usage. Terms like WebPKI exist specifically to make that distinction since, for example, the U.S. government runs its own certificate authorities which are trusted by millions of clients and even some mainstream software (Adobe) but not browsers. This is far from unique as far as governments go, and in some cases may even be required within a country.
- teddyh 3y agoThose non-web CAs are not the topic of discussion, though. When we are discussing the DNSSEC PKI, we are not discussing any altroots¹. When people are discussing the CA system for TLS, they overwhelmingly mean the normal web CAs. 1. https://en.wikipedia.org/wiki/Alternative_DNS_root https://en.wikipedia.org/wiki/Alternative_DNS_root
- tptacek 3y ago"The normal web CAs" means "the Mozilla and Chrome root programs". There are other CAs, and some of them are even in the root stores of other browsers, but they're not "trusted" in the sense you meant upthread.
- shp0ngle 3y agoIf your threat includes nation states then DNSSEC is double-useless?