Earlier quoted context omitted.
That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.
and exactly what country is safe from the whims of politics? I was just reading about censorship in the Netherlands and other Euro states because of fear of offending religious people, especially muslims. If the far left Europeans can't protect speech, then who can? DNNSEC just enables centralized government control on a level that's not needed. DNS is fine as-is. Domain authentication should be done via the transpor…
Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
41–50 of 112 posts
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#42Earlier quoted context omitted.
Still sounds like an improvement over the current PKI where any CA can sign any cert for any domain. How many roots do you have in your browser's trust store? How many of them would roll over and mis-issue certs if presented with a secret warrant in their country of residence? (All of them.)
No. See: https://www.imperialviolet.org/2015/01/17/notdane.html There are 3873497 CAs your browser has to trust today. DANE adds a 3873498th and a 3873499th, and the ones it adds are controlled by NSA. The solution to the CA problem is to drastically reduce the power CAs have, which is what is happening with key pinning and certificate transparency and whatever follows that. The solution to the CA problem can't possi…
I agree that CAs + DANE is just as shitty or shitter than CAs.
But:
a) In the event DANE replaced the CA system, one super-CA controlled by the NSA is better than 300 CAs essentially controlled by 50 different governments including the NSA.
b) Nobody's making you use DANE. Signed DNS records are an improvement over the status quo regardless of what you think of tying TLS to it.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#43Earlier quoted context omitted.
How does DNSSEC give immense control over TLS keys to sites in those TLDs exactly? I think I'm missing something.
The motivating use case for DNSSEC is DANE. DANE stores TLS certificates in DNSSEC-signed DNS records. But the top of the DNSSEC tree is --- de jure! --- controlled by governments.
1. Get a signed CA certificate for your domain at gun-point.
2. Send a forged DNSSEC record?
In which case, it's not significantly worse than the current state? And even though we can't burn a TLD, we can burn the CA that signed the certificate in the first place?
Or is there some magic in DANE that subverts CA verification?
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#44Earlier quoted context omitted.
No. See: https://www.imperialviolet.org/2015/01/17/notdane.html There are 3873497 CAs your browser has to trust today. DANE adds a 3873498th and a 3873499th, and the ones it adds are controlled by NSA. The solution to the CA problem is to drastically reduce the power CAs have, which is what is happening with key pinning and certificate transparency and whatever follows that. The solution to the CA problem can't possi…
How does having a new super-CA controlled by the NSA impede key pinning and certificate transparency? I agree that CAs + DANE is just as shitty or shitter than CAs. But: a) In the event DANE replaced the CA system, one super-CA controlled by the NSA is better than 300 CAs essentially controlled by 50 different governments including the NSA. b) Nobody's making you use DANE. Signed DNS records are an improvement over t…
The difference between DNSSEC's government-controlled super CA and a normal TLS CA is that when Google spots a normal TLS CA misbehaving because of an alert from a broken pin or CT log, it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it. Both of these things have happened and will keep happening.
Google cannot do that to .COM or .IO. If the government-controlled super-CA that runs .COM misbehaves, we have no recourse.
DNSSEC essentially takes the worst feature of the HTTPS trust model and bakes it permanently into the core fabric of the Internet.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#45Earlier quoted context omitted.
and exactly what country is safe from the whims of politics? I was just reading about censorship in the Netherlands and other Euro states because of fear of offending religious people, especially muslims. If the far left Europeans can't protect speech, then who can? DNNSEC just enables centralized government control on a level that's not needed. DNS is fine as-is. Domain authentication should be done via the transpor…
Secure DNS allows a number of nice things that otherwise are a risk, such as trusting server SSH fingerprints without prompting on first use.
Because it's not like the USG would ever tamper with the DNS to further a policy goal, right?
http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#46Earlier quoted context omitted.
The motivating use case for DNSSEC is DANE. DANE stores TLS certificates in DNSSEC-signed DNS records. But the top of the DNSSEC tree is --- de jure! --- controlled by governments.
Wouldn't that require a nation state to: 1. Get a signed CA certificate for your domain at gun-point. 2. Send a forged DNSSEC record? In which case, it's not significantly worse than the current state? And even though we can't burn a TLD, we can burn the CA that signed the certificate in the first place? Or is there some magic in DANE that subverts CA verification?
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#47Earlier quoted context omitted.
Wouldn't that require a nation state to: 1. Get a signed CA certificate for your domain at gun-point. 2. Send a forged DNSSEC record? In which case, it's not significantly worse than the current state? And even though we can't burn a TLD, we can burn the CA that signed the certificate in the first place? Or is there some magic in DANE that subverts CA verification?
I don't understand your question. If the government can't subvert CAs, DNSSEC is pointless; let's all just rely on the CAs. It can subvert them. Now, what problem is DNSSEC solving?
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#48It's great to see this microsite (and the announcement yesterday) as this rollout by CloudFlare will do two major things to help move DNSSEC forward: 1. Simplify the process of setting up DNSSEC-signing for so many people; and 2. Advance the usage of stronger crypto through the used of ECDSA (DNSSEC algorithm 13). The first point will help with getting many more domains signed. The second point will help those of us…
1. The roots and TLDs remain RSA-keyed. 2. As recently as months ago, those keys were 1024-bit RSA. 3. If the zones above those Cloudflare manages are RSA, it doesn't matter if Cloudflare's own zones are ECDSA. 4. ECDSA is itself outmoded and dangerous.[1]. Cloudflare has the first significant deployment of curve-based DNS on the Internet, and because of standards group torpor, they're forced to use bad NIST-curve DS…
There was strong interest in changing the algorithm when the KSK is rolled (when that occurs is still to be decided), but for the moment an algorithm change will not be part of that.
I don't deny that deployment of ED25519 will take some time. Once approved it has to be integrated into the signing software. It's also got to be integrated into the validation side. It's going to take time. So lets get started!
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#49I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#50Earlier quoted context omitted.
1. The roots and TLDs remain RSA-keyed. 2. As recently as months ago, those keys were 1024-bit RSA. 3. If the zones above those Cloudflare manages are RSA, it doesn't matter if Cloudflare's own zones are ECDSA. 4. ECDSA is itself outmoded and dangerous.[1]. Cloudflare has the first significant deployment of curve-based DNS on the Internet, and because of standards group torpor, they're forced to use bad NIST-curve DS…
tptacek - the root keys will remain RSA-keyed for some time. The root Key Signing Key (KSK) is 2048-bit RSA. The root Zone Signing Keys (ZSKs) that are CHANGED every 3 months (a ZSK key ceremony is in fact happening TODAY ) are 1024-bit RSA. There was strong interest in changing the algorithm when the KSK is rolled (when that occurs is still to be decided), but for the moment an algorithm change will not be part of t…