4 ms·
Why didn't this catch on?
by quickthrower2 3y ago
Why didn't this catch on?
- eldridgea 3y agoI asked a cloudflare engineer this and the answer was a bit vague but amounted to the failure rate being something like 0.5% which was too high for the amount of TLS sessions being initiated all the time. Although I always thought it would be a nice feature for security conscious folks to be able to ennable. Or go ahead and use it on more sensitive sites only, e.g. banks.
- quickthrower2 3y agoWhich leads us back to needing caching, which needs a signatory, and a list of trusted signatory, which gets us back to certificate authorities. Gotcha :-).
- stephenr 3y agoCaching is something DNS already has in-hand.
- quickthrower2 3y agoUsing a distributed MITM system! https://www.cloudflare.com/en-au/learning/dns/dns-cache-poisoning/ https://www.cloudflare.com/en-au/learning/dns/dns-cache-pois...
- stephenr 3y agoPerhaps you're unaware, but that problem can be largely mitigated by DNSSEC, which is why it's considered a requirement to make DANE practical.
- CMCDragonkai 3y agoWhat were the circumstances of the failures?
- dc396 3y agoBrowser vendors weren't interested. They believed the additional latency of DNS lookups would impact customer conversion rates. DANE is catching on in the email world.
- tptacek 3y agoBecause (to a first approximation) nobody uses DNSSEC, which is required for DANE to work. The "why nots" of DNSSEC are many and varied, from reliability to low utility to vendor support.