5 ms·
> Browsers and operating systems aren't going to add full DNSSEC resolving caches. Actually they already did. OS X for instance has this baked into mDNSRespond
by blumentopf 12y ago
> Browsers and operating systems aren't going to add full DNSSEC resolving caches.
Actually they already did. OS X for instance has this baked into mDNSResponder.
- tptacek 12y agoFire up a terminal, run "tcpdump -s0 -i en0 udp", open Safari, resolve "www.enteract.com", and tell me if you see a full recursive DNS lookup happening, or if instead you see Safari's stub resolver asking the DHCP-configured DNS cache server for help over the insecure Internet.
- blumentopf 12y agomDNSResponder supports DNSSEC validation, please look at the source code: http://opensource.apple.com/source/mDNSResponder/mDNSResponder-522.92.1/mDNSMacOSX/DNSSECSupport.c http://opensource.apple.com/source/mDNSResponder/mDNSRespond...
- tptacek 12y agoThis is like saying "everyone can just run their own DNS server". Of course, as I said, they won't. The fact that Apple has a DNSSEC-resolving recursive lookup server and Safari doesn't use it strengthens my point instead of weakening it.
- tedunangst 12y agoThat doesn't really respond to the point. Does Safari use DNSSEC or not?
- blumentopf 12y agoOf course it does, Safari uses the resolver provided by OS X, which is mDNSResponder. (It superseded the stub resolver in libSystem.dylib starting with 10.6.)
- sffho 12y agoYou are mistaken. https://news.ycombinator.com/item?id=8896092 https://news.ycombinator.com/item?id=8896092
- tedunangst 12y agoHow's that saying go about only proving the code correct, but not testing it? I think there's a reason tptacek specifically asked about tcpdump of on wire traffic.
- sffho 12y ago> Actually they already did. OS X for instance has this baked into mDNSResponder. That's not altogether true and now also irrelevant. mDNSResponder has DNSSEC support that isn't quite baked and was not enabled by default. The only way to use the support it did provide was by passing specific flags to a relatively low-level API. (You'd have to configure the system to use a DNSSEC enabled resolver as well of course.) mDNSResponder has been replaced by discoveryd which does not have any DNSSEC support (other than silently accepting the validate flags). Perhaps it'll gain further support in the future. If it does I'd not bet on it being enabled by default any time soon.