Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

11–20 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#13
post #5

Why not DNSCurve? http://dnscurve.org I mean, I feel like adoption is so low for DNSSEC already - does it even matter if it's 0% for DNSCurve or 1% adoption for DNSSEC? Why even bother with a 20 year old protocol?

Sounds like a better option. Why should I trust a single company when there are open source non-profit alternative?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#14
post #5

Why not DNSCurve? http://dnscurve.org I mean, I feel like adoption is so low for DNSSEC already - does it even matter if it's 0% for DNSCurve or 1% adoption for DNSSEC? Why even bother with a 20 year old protocol?

Sounds like a better option. Why should I trust a single company when there are open source non-profit alternative?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#16
post #3

Does this seem ironic to anyone else considering CloudFlares SSL offering essentially is a MITM attack?

The essense of "MITM" isn't the Middle but the fact that the Man is unauthorized, Eve to Alice and Bob. If Alice and Bob agree to put CloudFlare (oh, look, the C already works!) in between them, there's a Middle but there's no [unauthorized] Man.

SSL's purpose isn't to create some sort of quasi-mythical "direct connection" between Alice and Bob, it's just removing the general Internet as a vector for many attacks. An utterly critical building block of the global Internet, but nothing more; certainly not a magic invocation that casts the spell of Security +1 across the entire communication, neither in fact nor in intent.

It's worth taking a moment to try to explore what the idea of "direct connection" is that you have in your head, in a world where Bob is probably already a program generating HTTP with no human interaction in an arbitrarily-complicated manner, with arbitrarily-complicated combinations of SSL accelerators, WAFs, and whoknows what other network appliances, even before we consider what it means to assemble a page from JS and images from 10 different domains representing other entities, and where Alice is using a browser and arbitrary plugins, each of which she is implicitly trusting, and possibly a proxy. If you examine this closely it becomes surprisingly complicated.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#18
post #17

Dupe of https://news.ycombinator.com/item?id=10539245 ?

This is a post of the DNSSEC microsite containing a bunch of information (not sure who the poster is, it's not someone from CloudFlare) whereas that's a link the announcement blog.
Post reply on HN