3 ms·
DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions. https://soc
by dsl 22d ago
DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions.
https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- apefulsin 22d agoSo DNS should be open to MITM attackers?
- icedchai 22d agoEven with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/ https://blog.cloudflare.com/de-tld-outage-dnssec/
- digitalPhonix 21d agoDid you read the article? It's saying that DNSSEC as an implementation to prevent MITM is flawed; other solutions that protect against MITM are proposed.
- teddyh 22d agoRebuttal: <https://easydns.com/blog/2015/08/06/for-dnssec/ https://easydns.com/blog/2015/08/06/for-dnssec/>
- dsl 22d agoThat rebuttal held water 10 years ago, but fortunately we have made a lot of advancements since then. DNSSEC was a solution trying to solve the problem of DNS security while still maintaining transparency for DNS operators to spy on queries. At the time, passive DNS was one of the tent poles of tracking malware and responding to security incidents. We have since committed entirely to transport security in the form of DoH and friends. It solves the vast majority of problems we actually have.
- thayne 21d agoDoH only secures the connection between the DoH provider and the client, not the response from the authoritative DNS server. It also isn't sufficient for DANE or similar. So DoH doesn't completely solve the problems DNSSEC tried to.
- wildylion 21d agoExactly. And now there's <https://datatracker.ietf.org/doc/html/rfc9539 https://datatracker.ietf.org/doc/html/rfc9539> that allows encrypted DNS between authoritative and recursive servers as well.
- thayne 21d agoThat provides privacy, but not authentication.
- dsl 18d agoAuthentication was never the problem, transport security was. This is why we pushed to deploy TLS everywhere instead of focusing on a scheme to PGP sign every webpage on the internet.
- thayne 18d agoAuthentication is precisely the problem DNSSEC is supposed to solve. And authentication is part of transport security. TLS usually does provide authentication. The certificate is signed by a chain that leads up to a trusted CA, and content of the stream is authenticated using an AEAD encryption algorithm. But RFC 9539 specifically doesn't require the certificate to be signed by a CA (and recommends using a self signed cert) or the client to verify the authenticity of the certificate used by the server. This means that an active MitM could return whatever it wanted to the recursive resolver. Pulling that off is admittedly more difficult than a MitM on a public wifi network at a coffee shop, but it's still a gap in security. And no, you can't just use Web PKI to verify connections to authoritative DNS servers, because Web PKI relies on DNS to confirm domain ownership.
- Stitch4223 22d agoSuch as? And do those solve the same thing? The post lists 8 headlines why it should be abolished.
- miniBill 20d ago> Had DNSSEC been deployed 5 years ago, Muammar Gaddafi would have controlled BIT.LY’s TLS keys. Yupp. Which is why using bit.ly is a terrible idea unless you live in Lybia