5 ms·
Who in the industry, whether they are "financially aligned" or not, claims that DNSSEC provides you with privacy or encryption? The DNS data is sent in the clea
by kijeda 12y ago
Who in the industry, whether they are "financially aligned" or not, claims that DNSSEC provides you with privacy or encryption? The DNS data is sent in the clear.
No-one who uses DNSSEC is arguing it keeps your DNS records private. It is a straw man argument to suggest otherwise.
DNSSEC is designed to provide tamper-evidence, not privacy.
- tptacek 12y agoIt's not a straw man to point out that the protocol that ostensibly "secures the DNS" does not in fact encrypt DNS queries or responses. I wasn't merely saying that DNSSEC records are plaintext (though they are). I was pointing out that the last mile from server to resolver has no cryptography whatsoever. Resolvers don't speak DNSSEC to servers --- it's a server-to-server protocol. This is a common tactic among DNSSEC advocates. Observation oft he inexplicable lack of last-mile security --- the one place where the Internet could actually benefit from DNS security --- is dismissed as a "straw man". Yes, it's very inconvenient to arguments for DNSSEC adoption. No, that doesn't make it out-of-bounds.
- danyork 12y ago> This is a common tactic among DNSSEC advocates. Hmm... as a "DNSSEC advocate", I can say that I've never dismissed the lack of last-mile security as a "straw man". It's a real issue - but NOT one that DNSSEC seeks to solve. Because of this issue, many of us who advocate DNSSEC also advocate that the DNSSEC validation happens as close as possible to the end user, including even within the applications used by the user. If not in the apps then in the operating system. And if not there then on the local network... but then you start expanding the zone of risk. For the DNSSEC integrity validation to be useful it needs to happen as close as possible to the user - OR have a secured connection between the user and their DNS resolver. From a DNSSEC advocacy point of view, I'm always glad when a provider of DNS resolvers turns on DNSSEC validation... but public DNS servers are farther away from the end user than I would personally like to see. It's a good first step... but we really need the integrity validation happening close to the user.
- tptacek 12y agoA protocol already exists that does a significantly better job both of providing query integrity and confidentiality on the "last mile" for DNS: it's DNSCurve. DNSSEC on the other hand is almost perfectly unsuited for last mile security, requiring as it does every enabled resolver to act as it's own fully recursive cache. DNSSEC almost petulantly fails to provide confidentiality, too. 2014 advocacy for DNSSEC seems to me like distilled sunk-cost fallacy. It sucks that people spent 2 entire decades working on this protocol (most of the design is still traceable to TIS!), but they did, and it didn't work out, and now they should move on. The manifold weaknesses of DNSSEC are completely unnecessary. The protocol has no meaningful deployment. Inflicting it on the internet in 2014 would be a grave and unforced error. Do better.
- danyork 12y agoThomas, DNSSEC has nothing to do with last-mile security, nor does it have anything to do with confidentiality. You know that. Neither of those is the problem DNSSEC solves. > 2014 advocacy for DNSSEC seems to me like distilled sunk-cost fallacy. 2014 advocacy for DNSSEC is merely a continuation of advocacy that has been going on for years now. The root zone of DNS was only signed 4 years ago. It's taken those 4 years to get almost all the gTLDs signed and 2/3rds of the ccTLDs signed. It's taken those years to get the DNSSEC-related tools to the point where the configuration and deployment is as simple as it is now. It's taken those 4 years to get the pieces in place where it can work well... and there's still more work to do. > The manifold weaknesses of DNSSEC are completely unnecessary. The protocol has no meaningful deployment. I've quoted many deployment statistics in other parts of this thread. You dismiss them. That is your right. But to say it has "no meaningful deployment" is to dismiss the great amount of work that has happened all over the world by developers and network operators who DO see DNSSEC as something useful. To go back to one I've quoted here - there are 18 million Comcast customers in the USA that have all of their DNS queries validated by DNSSEC. To me that is a meaningful deployment. > Inflicting it on the internet in 2014 would be a grave and unforced error. Do better. We are doing better. In the view of myself and many others, DNSSEC makes the Internet more secure. We're implementing it. We're deploying it. If you've got a better idea bring it to the IETF and lets have the debate in the standards mailing lists.