3 ms·
huh? No, for DANE it is required to have DNSSEC in place. Also read the last sentence of my previous statement again.
by voidz 11y ago
huh? No, for DANE it is required to have DNSSEC in place. Also read the last sentence of my previous statement again.
- realityking 11y agoAnd now you're trusting the registrar, the registry and ICANN. It's always pick a poison. Also, DNSSEC still has some severe issues in practice. I'd be glad if we could get DANE widely deployed for mail servers. Edit: Oh, and if you're not using a validating resolver yourself you're also trusting that you're ISP is using one and not manipulating the responses.
- marcosdumay 11y ago> Oh, and if you're not using a validating resolver yourself you're also trusting that you're ISP is using one and not manipulating the responses. I really don't understand why people keep repeating that complaint. Of course, if you don't check the keys you don't get any security. How is that a problem of the algorithm? And how is that a problem on practice? If you want some real amount of security you check the keys, being them SSL certificates, DNSSEC signatures, or whatever else encryption system people put on place.
- realityking 11y agoYou're speaking from the perspective of somebody who could set this up for himself. "Normal" people don't know stuff like this, but we can't leave them unprotected. That's why DANE for mailserver is such an attractive target. They're usually run by people who know what they're doing and it helps bring a lot of infrastructure into place.
- marcosdumay 11y agoThe point is that there's nothing for normal people to setup (or, at least, it does not have to be). Your email software should verify DANE keys, just like your browser verifies TLS keys. The fact that current software is hard of configure is just a symptom that it's badly designed. The only inherently hard thing in DNSSEC is distributing your domain data (not really harder than setting our server for TLS), and normal people do not do that.
- TheSpiceIsLife 11y agoYou still have to trust someone. I think the trust model is broken for the same reason it can be said three can keep a secret, if two of them are dead. How can humans create a software or hardware system that absolves us of the issue of trust, when people are, and have always, been up to no good. The courts are full of people who claim other people have acted outside of good judgement. I don't think it's possible to have trust without its opposite. I'd like to be proven wrong.