3 ms·
> it is almost never mentioned that the security of TLS is completely dependent on an extremely insecure protocol like DNS Yes, the most likely reason for tha
by PreInternet01 2y ago
> it is almost never mentioned that the security of TLS is completely dependent on an extremely insecure protocol like DNS
Yes, the most likely reason for that being that... it isn't true? The CA ecosystem is fairly resilient against DNS and even BGP hijacks, and simply ignoring innovations like CT is... not persuasive.
> With DANE you can tell the sending mail server that TLS is available
Yeah, or you just refuse to send and receive any email without STARTTLS being in effect. You won't miss much.
- alexey-salmin 2y agoCT is a passive tool that doesn't really help to prevent incidents. In the 2017 Brazilian bank hack [1] Let's Encrypt denied any wrongdoing and clearly stated that DV means nothing more than DV (that is reasonable). These certificates were logged in CT but it was only discovered afterwards. [1] https://www.wired.com/2017/04/hackers-hijacked-banks-entire-online-operation/ https://www.wired.com/2017/04/hackers-hijacked-banks-entire-...
- mkj 2y ago"Kaspersky believes the attackers compromised the bank's account at Registro.br" I don't think DNSSEC would have helped there either. That's an interesting case study, thanks for posting it.
- tptacek 2y agoCT alters the economics of large-scale misissuance, actively, by creating consequences for it. CAs have been distrusted for issues detected by CT. That's not "passive".
- TheNewsIsHere 2y agoYou’re right. I would suggest that the commenter is right in spirit but the framing and the word “passive” aren’t compatible. CT is passive in that it provides an ability to be reactive, but it isn’t a proactive technology. It can’t “actively” do anything other than tell you something has happened.
- phicoh 2y agoHere is a recent attack showing the lack of resilience in the CA ecosystem: https://freedom-to-tinker.com/2022/03/09/attackers-exploit-fundamental-flaw-in-the-webs-security-to-steal-2-million-in-cryptocurrency/ https://freedom-to-tinker.com/2022/03/09/attackers-exploit-f... With password resets your own mail server is not involved. STARTTLS or not. In the absence of DANE, mail servers will not require or validate certificates. So the reset link will get to the attacker in the vast majority of cases.
- PreInternet01 2y agoYeah, password reset emails are sure a huge vulnerability. Nothing to do with DANE, though, since that won't solve that issue either (not going to spell out all the reasons for that, but suffice to say that once a zone's registrar account is compromised, as with all examples so far here, the 'turn off DNSSEC' option is even deadlier than all other extremely practical attacks otherwise possible against the protocol...)
- tptacek 2y agoThese are attackers exploiting BGP. They can bypass DNSSEC, too. DNS is control of names; BGP is control of the underlying IPs.
- phicoh 2y agoMaybe you can be a bit more specific and explain how exploiting BGP can change the CAA record in a DNSSEC secured zone? ACME validation with dns-01 relies only on DNS. Routing does not matter other than to create DoS.
- PreInternet01 2y agoIt's simply one more step in an attack chain. Again, all of the examples mentioned upthread involve compromising the zone's registrar accounts (through old-fashioned 'spear-phishing', which works regardless of DNSSEC, DANE, 2FA, or whatever -- otherwise, we wouldn't be reading about it!). The argument "well, they were able to compromise BGP, but DANE surely would have stopped them" is not only unsupported, but not particularly likely either.