3 ms·
> That's it. That is all that DNSSEC does. Thus providing an interesting foundation to build upon, for example DANE or SSHFP. Not very known or common things,
by redprince 3y ago
> That's it. That is all that DNSSEC does.
Thus providing an interesting foundation to build upon, for example DANE or SSHFP. Not very known or common things, but they show the potential of what is possible when there's a way to publish cryptographically authenticated records in DNS.
- peanut-walrus 3y agoIn both cases what it boils down to is that "it's an alternative to the current CA system". Sure, alternatives are good, but why does it need to be coupled to DNS? If I have a .ly domain, do I really want to be forced to trust the Libyan government for my security?
- deleted 3y ago[deleted]
- teddyh 3y agoWhat do think a ccTLD is, if not a TLD controlled by a country, meaning the government of that country? In what world would it be reasonable for you to have a .ly domain and not trust the Libyan government not to do whatever they like to your domain? Like, you know, everybody already does with every .com and the U.S. government?
- peanut-walrus 3y agoBut that is exactly the point: in the world we are in right now, I DON'T have to trust the TLD operator to make sure my services are secure. Sure, there is a risk that the TLD operator will shut down my domain completely, but that is a different risk from the TLD operator MitM-ing my services. If my CA misbehaves? I can use a different CA. Not trivial, but doable. What if my TLD operator misbehaves or TLD changes ownership (like the .org case a few years ago) - change my domain?
- teddyh 3y ago> What if my TLD operator misbehaves or TLD changes ownership (like the .org case a few years ago) - change my domain? That already happens all the time. And when it does happen, the new owner can get a legitimate certificate for it.
- NavinF 3y agoUnder today's CA system the gov't can't MiTM without getting noticed on the certificate transparency logs. There's no equivalent for DNSSEC.
- NavinF 3y agoDANE isn't happening. Browsers tried a decade ago and gave up: https://www.imperialviolet.org/2015/01/17/notdane.html https://www.imperialviolet.org/2015/01/17/notdane.html
- deleted 3y ago[deleted]
- redprince 3y ago> DANE isn't happening. Browsers tried a decade ago and gave up DANE was never limited to browsers. Example: https://ssl-tools.net/mailservers/proton.me https://ssl-tools.net/mailservers/proton.me Though support in that space is very patchy as well and maybe going nowhere. In any case, it serves as an example that DNSSEC can be built upon, even if the new ideas don't necessarily make it.
- tptacek 3y agoThe major mail vendors came up with MTA-STS specifically to avoid having to roll out DNSSEC.