3 ms·
I must be early. There's not a single tptacek DNSSEC rant in this thread yet.
by pocksuppet 5mo ago
I must be early. There's not a single tptacek DNSSEC rant in this thread yet.
- aberoham 5mo agoHe’s busy with MathAcademy earning XP-SEC
- mike-cardwell 5mo agoPerhaps he's moribund
- deleted 5mo ago[deleted]
- 0123456789ABCDE 5mo agodoesn't this event speak for itself though?
- Avamander 5mo agoKind-of. But there are worse things than outages when it's PKIs we're talking about. DNSSEC is also extremely opaque and unmonitored. Any compromise will not be noticed. Nor will anyone have any recourse against misbehaving roots. Fun fact, CloudFlare has used the same KSK for zones it serves more than a decade now.
- daneel_w 5mo agoWhich is fine. Not because KSK rollover is supposedly complicated, but if you can't manage to keep your private keys and PKI safe in the first place then key rotation is just a security circus trick. But if you do know how to keep them safe, then...
- Avamander 5mo agoIt is not fine. Keeping key material safe is not a boolean between "permanently safe" and "leaks immediately". Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade.
- cyberax 5mo ago> Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. Nope. Key material rotation is just circus when it's done for the sake of rotation. > For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade. Or maybe an employee has compromised the new key that is going to be rotated in, while the old key is securely rooted in an HSM?
- tptacek 5mo agoThe point of rotation for these kinds of keys is that it limits the blast radius of what happens if an employee compromises such a key. This is sort of like how there are one or two die-hard PGP advocates who have come up with a whole Cinematic Universe where authenticated encryption is problematic ("it breaks error recovery! it's usually not what you want!") because mainstream PGP doesn't do it. Except here, it's that key rotation is bad, because of how often DNSSEC has failed to successfully pull off coordinated key rotations.
- cyberax 5mo agoI can see the periodic rotations used as a way to keep up the operational experience. This is indeed a valid reason, although it needs to be weighted against the increased risk of compromise due to the rotation procedure itself. I'm just saying that rotating the key just in case someone compromised it is not a great idea. Doubly so if it's done infrequently enough for the operational experience to atrophy between rotations. And yeah, I fully agree that anything surrounding the DNSSEC operations is a burning trash fire. It doesn't have to be this way, but it is.
- pocksuppet 5mo agoLet's Encrypt going down isn't equivalent to a rant about how encryption was a terrible idea from the very beginning and we should all just use unencrypted traffic.
- tptacek 5mo agoPretty sure that rant doesn't exist.
- greensh 5mo agoIt does kinda? at least the part about to much security and it's really funny: https://tom7.org/httpv/httpv.pdf https://tom7.org/httpv/httpv.pdf also available as Video on YouTube.
- sam_lowry_ 5mo agoI host my blog on HTTP/1.1 only. But I also have an amateur radio station and I listen occasionally to (unencrypted!) air traffic frequencies around nearby airport.
- deleted 5mo ago[deleted]
- 0123456789ABCDE 5mo agonot to disagree on the merits of encryption — i'm not a clown, but scripting.com is still port 80 only, and Dave is the type to write a rant
- account42 5mo agoNo?
- apaprocki 5mo agoMaybe he drank a little too much Malört with the DENIC team last night?
- tptacek 5mo agoWhat would I need to rant about? Sometimes the world does my ranting for me.
- petee 5mo agoPerhaps its more fair to call it 'passionate'. That said, the last few dnssec posts that got traction, tptacek tends to be at least 20% of the comments alone (ex, 55/259), ignoring word count. Today seems calm
- 0123456789ABCDE 5mo ago"When the enemy is making a false movement, we must take good care not to interrupt him." — some guy, you wouldn't have hear of him