5 ms·
Ask HN: Why SSL certs are not decentralized?
Maybe a noob question: Why SSL/TLS certs are not decentralized? Is it not possible to set public key in DNS TXT record and have private key on the server. Would that not solve encryption? Why do we need SSL / TLS certs from a CA like LetsEncrypt?
- aashutoshrathi 3y agothat's a fair question for me too. Same for DRM certificates
- stop50 3y ago1. An txt record adds more time to the request, since you can't start the request before opening an tls connection. 2. The browser has to go through all the TXT records. My domains already have 4-5 TXT records. 3. The dns is still pretty much insecure. Dnssec is still not always available
- stephenr 3y agoWhat you're talking about exists: it's called DANE: https://en.m.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities https://en.m.wikipedia.org/wiki/DNS-based_Authentication_of_...
- quickthrower2 3y agoWhy didn't this catch on?
- eldridgea 3y agoI asked a cloudflare engineer this and the answer was a bit vague but amounted to the failure rate being something like 0.5% which was too high for the amount of TLS sessions being initiated all the time. Although I always thought it would be a nice feature for security conscious folks to be able to ennable. Or go ahead and use it on more sensitive sites only, e.g. banks.
- quickthrower2 3y agoWhich leads us back to needing caching, which needs a signatory, and a list of trusted signatory, which gets us back to certificate authorities. Gotcha :-).
- stephenr 3y agoCaching is something DNS already has in-hand.
- quickthrower2 3y agoUsing a distributed MITM system! https://www.cloudflare.com/en-au/learning/dns/dns-cache-poisoning/ https://www.cloudflare.com/en-au/learning/dns/dns-cache-pois...
- stephenr 3y agoPerhaps you're unaware, but that problem can be largely mitigated by DNSSEC, which is why it's considered a requirement to make DANE practical.
- CMCDragonkai 3y agoWhat were the circumstances of the failures?
- dc396 3y agoBrowser vendors weren't interested. They believed the additional latency of DNS lookups would impact customer conversion rates. DANE is catching on in the email world.
- tptacek 3y agoBecause (to a first approximation) nobody uses DNSSEC, which is required for DANE to work. The "why nots" of DNSSEC are many and varied, from reliability to low utility to vendor support.
- neduma 3y agoInteresting.
- devneelpatel 3y agoThis is very interesting. Hope this catches on.
- neduma 3y agoI like the thinking and direction here. At least, we could use this in situations where root cert is not part of CA stores in os/browsers.
- makeworld 3y agoHow do you secure the DNS entries?
- stephenr 3y agoAs per DANE: you use DNSSEC.
- growse 3y agoI thought we were trying to decentralise?
- quickthrower2 3y agoDNS is not decentralised. You pay some rentseeker for your domain. You might be happier with NFT based domain names? Even then it is not decentralised because whoever wins that mind battle is then the defacto king of that DNS. Unless it is done carefully to avoid early squatting and premine.
- makeworld 3y agoWhich comes back to same CA problem the OP is trying to get rid of, no?
- stephenr 3y agoBecause you're reliant on the registrar and potentially a third party operator running the authoritative name servers? You're already reliant on those things, regardless of whether you want TLS or not. I am a very big proponent of building things yourself (rather than using an off-the-shelf/existing solution that's similar) - whether that is tooling, or applications, or hosting your own services, and I'm particularly vocal about not making your business be shackled to specific services run by others (e.g. I'm of the opinion that offering exclusively "social login" is a huge red flag), and even I don't start complaining about "well this stack isn't really self hosted, you're still relying on the registrar for your domain!"
- 1vuio0pswjnm7 3y agoPopular browsers are controlled by so-called "tech" companies that sell advertisiing services and seek to profit from online purchases. These so-called "tech" companies exert oversized control over the CA scheme. Pure coincidence.
- tptacek 3y agoThat's a funny thing to say, because (I think literally) every security advance in the WebPKI has come from browsers over the objection of CA operators. Like, you couldn't possibly get this wronger.
- 1vuio0pswjnm7 3y agohttps://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf https://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf "WebPKI" Is Going Just Great.
- jiggawatts 3y agoSimple: the financial interests of huge corporations like DigiCert. They sit in standards bodies that could fill their moat and undermine every open effort. It’s insidious and there’s not much anyone with less than a billions dollars of interest in the matter can do about it. Maybe a government or mega corp like Google will fix it, but I’m not holding my breath…
- xialvjun 3y agoWhy not use public key as IP. Like yggdrasil-go, use `public_key.sha256.first_63_bit === ipv6[1..64]` (maybe some data error but here is how it works). Well, yggdrasil is an overlay network, it can do that. But the ISP network cann't. Maybe we all should move to an overlay network.
- xialvjun 3y agowe can even add ipv8 ipv12 or ipv256 whatever, then `public_key.sha256 === ipv256`. So we can even have 0rtt in tls.
- cpach 3y agoIt’s not a trivial problem to solve. See Zooko’s triangle: https://en.wikipedia.org/wiki/Zooko%27s_triangle https://en.wikipedia.org/wiki/Zooko%27s_triangle and https://web.archive.org/web/20011020191610/http://zooko.com/distnames.html https://web.archive.org/web/20011020191610/http://zooko.com/...