7 ms·
Depend on one less third party, you still depend on the DNS Root servers, your ISP / hosting, domain registry, etc.
by vhcr 1y ago
Depend on one less third party, you still depend on the DNS Root servers, your ISP / hosting, domain registry, etc.
- michaelt 1y agoCAs are uniquely assertive about their right to cut off your access. My hosting provider may accidentally fuck up, but they'll apologise and fix it. My CA fucks up, they e-mail me at 7pm telling me I've got to fix their fuck-up for them by jumping through a bunch of hoops they have erected, and they'll only give me 16 hours to do it. Of course, you might argue my hosting provider has a much higher chance of fucking up....
- Uvix 1y agoCAs have to follow the baseline rules set by Google and Mozilla regarding incident response timelines. If they gave you more time, the browsers would drop them as a supported CA.
- michaelt 1y agoThe CAs have to follow the baseline rules set by the CA/Browser Forum which CAs are voting members of. Mark my words, some day soon an enterprising politician will notice the CA system can be drawn into trade sanctions against the enemy of the day....
- tialaramex 1y agoThe BRs already have a deliberate carve out where a CA can notify that their government requires them to break the rules and how they'll do that, and then the browsers, on behalf of relying parties can take whatever action they deem appropriate. If you're required to (or choose to) not tell us about it, because of active monitoring when we notice it's likely your CA will be distrusted for not telling us, this is easier because there's a mechanism to tell us about it - same way that there's a way to officially notify the US that you're a spy, so, when you don't (because duh you're a spy) you're screwed 'cos you didn't follow the rules. The tech centralization under the US government does mean there's a vulnerability on the browser side, but I wouldn't speculate about how long that would last if there's a big problem.
- Dylan16807 1y agoSo what does "CA fixes the problem" look like in your head? Because they'll give you a new certificate right away. You have to install it, but you can automate that, and it's hard to imagine any way they could help that would be better than automation. What else do you want them to do? Asking them to not revoke incorrect or compromised certificates isn't good for maintaining security.
- michaelt 1y agoImagine if, hypothetically speaking, the CA had given you a certificate based on a DNS-01 challenge, but when generating and validating the challenge record they'd forgotten to prefix it with an underscore. Which could have lead to a a certificate being issued to the wrong person if your website was a service like dyndns that lets users create custom subdomains. Except (a) your website doesn't let users create custom subdomains; (b) as the certificate is now in use, you the certificate holder have demonstrated control over the web server as surely as a HTTP-01 challenge would; (c) you have accounts and contracts and payment information all confirming you are who you say you are; and (d) there is no suggestion whatsoever that the certificate was issued to the wrong person. And you could have gotten a certificate for free from Lets Encrypt, if you had automatic certificate rotation in place - you paid $500 for a 12-month certificate because you don't. An organisation with common sense policies might not need to revoke such a certificate at all, let alone revoke it with only hours of notice.
- Dylan16807 1y agoYou didn't answer my question. What would the CA fixing it look like? Your hosting example had the company fix problems, not ignore them. And have you seen how many actual security problems CAs have refused to revoke in the last few years? Holding them to their agreements is important, even if a specific mistake isn't a security problem [for specific clients]. Letting them haggle over the security impact of every mistake is much more hassle than it's worth. > if you had automatic certificate rotation in place - you paid $500 for a 12-month certificate because you don't Then in this hypothetical I made a mistake and I should fix it for next time. And I should be pretty mad at my CA for giving me an invalid certificate. Was there an SLA?
- treve 1y agoIf you think about it the spirit of the internet is based on collaboration with other parties. If you want no third parties, there's always file: and localhost.
- 1vuio0pswjnm7 1y agoThird party root servers are generally used for looking up TLD nameservers, not for looking up domainnames registered to individuals publishing personal blogs^1 Fortunately, one can publish on the www without using ICANN DNS For example http://199.233.217.201 http://199.233.217.201 or https://199.233.217.201 https://199.233.217.201 1. I have run own root server for over 15 years An individual cannot even mention choosing to publish a personal blog over HTTP without being subjected to a kneejerk barrage of inane blather. This is truly a sad state of affairs I'm experimenting with non-TLS, per packet encryption with a mechanism for built-in virtual hosting (no SNI) and collision-proof "domainnames" on the home network as a reminder that TLS is not the only way to do HTTPS It's true we depend on ISPs for internet service but that's not a reason to let an unlimited number of _additional_ third parties intermediate and surveil everything we do over the internet
- JakaJancar 1y agoYou have some weird definition of "root".
- deleted 1y ago[deleted]
- aragilar 1y agohttps://en.wikipedia.org/wiki/Alternative_DNS_root https://en.wikipedia.org/wiki/Alternative_DNS_root, so you could (and people have/are) run your own root server.
- JoshTriplett 1y ago> inane blather And this is why it's a good thing that every major browser will make it more and more painful, precisely so that instead of arguments about it, we'll just have people deciding whether they want their sites accessible by others or not. Unencrypted protocols are being successfully deprecated.
- 1vuio0pswjnm7 1y agoDefinition of "root server" Authoritative DNS nameserver that serves root.zone, e.g., the one provided by ICANN, or maybe a customised one In own case it is served only to me on local network Many years ago, one of the former ICANN board members mentioned on his personal blog running his own root
- MYEUHD 1y agoHost an onion website at home using solar energy, and the only third party your website will depend on is your internet provider :)
- 01HNNWZ0MV43FF 1y agoAnd an army of volunteers and feds to run relays
- kelnos 1y agoWhat about all the third parties running relays and exit nodes?
- wongogue 1y agoI gave up trying to build a solar panel.
- bawolff 1y agoWhat about the Tor directory authorities? There is no magic do it all yourself. Communicating with people implies dependence.
- Ajedi32 1y agoOnion websites also don't need TLS (they have their own built-in encryption) so that solves the previous commenter's complaint too. Add in decentralized mesh networking and it might actually be possible to eliminate the dependency on an ISP too.
- philipallstar 1y ago> they have their own built-in encryption What does this mean? Is that encryption not reliant on any third parties, or is it just relying on different third parties?
- bombcar 1y agoThe onion URL is itself a public key - https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/ https://protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7... for example. Proton Mail burned CPU time until they found a public key that started the way they wanted it to. So that is the public key for an HTTPS equivalent as part of the tor protocol. You can ALSO get an HTTPS certificate for an onion URL; a few providers offer it. But it’s not necessary for security - it does provide some additional verification (perhaps).
- sam_lowry_ 1y agoLet's Encrypt pushes me to run its self-updating certbot on my personal server, which is a big no-go. I know about acme.sh, but still...
- rascul 1y agoThere is a plethora of other clients besides certbot or acme.sh.
- rpdillon 1y agoI counted by hand, so it might be wrong, but they appear to list and link to 86 different ACME client implementations across more than a dozen languages: https://letsencrypt.org/docs/client-options/ https://letsencrypt.org/docs/client-options/ I've used their stuff since it came out and never used certbot, FWIW. If I were to set something up today, I'd probably use https://github.com/dehydrated-io/dehydrated https://github.com/dehydrated-io/dehydrated.
- bruce511 1y agoPlus, it's one of the easier protocols to implement. I implemented it myself, and it didn't take long. So you're absolutely not dependent on the client software, or indeed anyone else's client software.
- tialaramex 1y agoThey're focused on the thing that'll get the most people up and running for the least extra work from them. When you say "push" do you just mean that's the default or are they trying to get you to not use another ACME client like acme.sh or one built in to servers you run anyway or indeed rolling your own? Like, the default for cars almost everywhere is you buy one made by some car manufacturer like Ford or Toyota or somebody, but usually making your own car is legal, it's just annoyingly difficult and so you don't do that.
- cube00 1y ago>usually making your own car is legal It may be legal but good luck ever getting registration for it.