4 ms·
I can not forgive Adam he removed the DANE support from Chrome in spite of fact that he was the author of the draft standard http://datatracker.ietf.org/wg/dan
by zhovner 13y ago
I can not forgive Adam he removed the DANE support from Chrome in spite of fact that he was the author of the draft standard http://datatracker.ietf.org/wg/dane/ http://datatracker.ietf.org/wg/dane/
- tptacek 13y agoWhy does Langley need your forgiveness for not supporting DANE? DANE is arguably worse than X.509 CAs.
- tikums 13y agoHow is it worse than X.509?
- marshray 13y agoHere we go again :-)
- denibertovic 13y agocan anyone point to a link that explains X.509 s shortcomings? I'd really like to read up on that but can't find any sane info.
- marshray 13y agoHaha consider the possibility that some of the insane ranting you hear about x.509 is actually balanced and accurate criticism :-)
- denibertovic 13y agohehe, so true.
- tikums 13y agoHow is it worse than X.509?
- tikums 13y agoHow is it worse than X.509?
- tikums 13y agoHow is it worse than X.509?
- 9h1d9j809s 13y agoWhy? Because DNSSEC can be attacked by the DNS root? It seemed to be our best attempt to get SSL for every website. CA-based certificates just won't cut it.
- tptacek 13y agoBecause replacing a PKI run by companies that the NSA can coerce with a PKI run by the US Government doesn't seem like a good plan? That, along with the litany of reasons why DNSSEC is a terrible design; that it doesn't secure queries from stub resolvers where the need is greatest; that it publishes internal zone names; that it breaks the resolver API and will inevitably create outages; I can go on. (I doubt this is what's held up DANE; rather, the unreliability of DNS compared to hyper-optimized HTTPS/TLS connections is the issue there; browser vendors care about milliseconds.)