Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

71–80 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#71
post #45

Earlier quoted context omitted.

Secure DNS allows a number of nice things that otherwise are a risk, such as trusting server SSH fingerprints without prompting on first use.

And to get that feature all you have to do is trust that the government that controls your TLD isn't going to fuck you. Because it's not like the USG would ever tamper with the DNS to further a policy goal, right? http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...

The nice thing about DNSSEC and the ccTLDs is that you can pick what country you trust. So you can get a domain in a country that is compatible with what you are trying to do.

Of course, with domain validated SSL certificates, you also have to trust DNS completely, because anyone who controls your domain can get a cert for that domain.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#72

Earlier quoted context omitted.

Come work at CloudFlare! Let's get working on that.

Are you serious about that?

We're interested in making the Internet more secure. Go look at our history. Why would we not be thinking about ways to secure DNS etc. further?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#73
post #69

Earlier quoted context omitted.

Okay, so this is what happens: 1. Evil NSA compromises CA in BFE 2. Evil NSA subverts DNSSEC for COM to publish a bad CA certificate 3. Some combination of Google Certificate Transparency + HPKP discovers this, the CA in BFE gets removed from browsers If your point is "DNSSEC is pointless", OK. But it sounds like you're saying it makes us less secure. I'm just trying to figure out how that could even be.

I'm not sure why your question is being side-stepped, I also had the same wonder. It seems from reading though that the reason this is a problem is CAs are not involved at all in the DANE/TLS scenario. Instead, the X.509 cert. stored in DNS is trusted for TLS purposes simply because it is DNSSEC signed rather than CA issued. However, it seems at this time, no mainstream browser actually supports this natively (some h…

> Instead, the X.509 cert. stored in DNS is trusted for TLS purposes simply because it is DNSSEC signed rather than CA issued.

And I would see that as a huge mistake. Requiring two layers of verification (DNSSEC + separate CA) is what had I assumed DNSSEC would do.

Would that stop the NSA? Probably not, but the person who broke DigiNotar wasn't exactly NSA.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#74
post #51
post #49

Earlier quoted context omitted.

With the current system, they can just seize the domain and get a certificate for it.

No. Seizing the domain does not help them if millions of browsers have the correct certificate pinned. Meanwhile: we're all pretty unhappy that the USG does just seize domains. How can it possibly be reasonable for us to support a forklift upgrade of a core protocol that burns that capability permanently and cryptographically into the core of the Internet?

Unless you have a short life 90 day cert from LetsEncrypt.org then your pinning doesn't last very long.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#75
post #30

Earlier quoted context omitted.

That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.

"DNSSEC: everything will be fine as long as everyone moves to domains in Bouvet Island's .BV. Brought to you by Cloudflare."

> The centre of the island is an ice-filled crater of an inactive volcano.

Sounds like a combination of the Fortress of Solitude and SPECTRE's volcano base.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#76
post #50

Earlier quoted context omitted.

How about, instead of getting started, we accept that DNSSEC is a failed 21-year-long experiment, and figure out a better way to get the moral equivalent of HSTS and HPKP for email links?

In the event that DNSSEC is adopted, what would the best course of action be to protect sites?

The concern I have with DNSSEC is that if it's adopted --- where "adopted" means "by the major email providers and by browsers" --- there's not much you can do to protect yourself from the SIGINT agencies that control the top of the DNS tree.

If there was a significant benefit to users for DNSSEC adoption, I'd be my normal tedious "maybe it's good, maybe it's bad" self. But the benefits aren't there. Instead, DNSSEC will impose immense operational costs and in some ways reduce security:

https://news.ycombinator.com/item?id=10541719

This isn't a hard decision and I don't have a hard time siding with the anti-surveillance crowd on it.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#77
post #57

Earlier quoted context omitted.

One thing I love about DNSSEC threads is that I get to join the anti-NSA faction on HN. Unlike you, I do not trust the giant corporation that controls .COM under charter from the US Government. The USG has repeatedly abused its trust, often directly with respect to .COM. The Internet has not fled .COM. The idea that we would deploy a forklift upgrade of a core protocol, at immense expense (look at Cloudflare's own ma…

Once we deploy it, any notion of solving the problem correctly dies. This seems to be the nut of the disagreement. Why do you expect that to be the case? Will good people like Marlinspike decide to just hang it up and throw in the towel now that CloudFlare have rolled out another service? Will CloudFlare themselves decide this is the last new security measure that anyone would ever want? So far I have seen no technic…

I don't know. Why don't you ask Moxie Marlinspike, who frequently comments on HN, what he thinks of DNSSEC?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#78
post #51

Earlier quoted context omitted.

No. Seizing the domain does not help them if millions of browsers have the correct certificate pinned. Meanwhile: we're all pretty unhappy that the USG does just seize domains. How can it possibly be reasonable for us to support a forklift upgrade of a core protocol that burns that capability permanently and cryptographically into the core of the Internet?

Unless you have a short life 90 day cert from LetsEncrypt.org then your pinning doesn't last very long.

I'm not sure what your argument is. Can you restate it?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#79
post #45

Earlier quoted context omitted.

And to get that feature all you have to do is trust that the government that controls your TLD isn't going to fuck you. Because it's not like the USG would ever tamper with the DNS to further a policy goal, right? http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...

That's the trust that government always requires. Being on the internet doesn't change the fact that the point of government is a monopoly on authorized use of force. They can always just send men with guns to your office, DNSSEC or no. If you don't trust your government not to abuse their power, that's not a problem that Cloudflare can help you with.

We're required to trust them for the DNS today. We aren't required to trust them for TLS keys. But DNSSEC/DANE formally and irrevocably gives them that authority.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#80
post #57

Earlier quoted context omitted.

One thing I love about DNSSEC threads is that I get to join the anti-NSA faction on HN. Unlike you, I do not trust the giant corporation that controls .COM under charter from the US Government. The USG has repeatedly abused its trust, often directly with respect to .COM. The Internet has not fled .COM. The idea that we would deploy a forklift upgrade of a core protocol, at immense expense (look at Cloudflare's own ma…

Once we deploy it, any notion of solving the problem correctly dies. This seems to be the nut of the disagreement. Why do you expect that to be the case? Will good people like Marlinspike decide to just hang it up and throw in the towel now that CloudFlare have rolled out another service? Will CloudFlare themselves decide this is the last new security measure that anyone would ever want? So far I have seen no technic…

[deleted]
Post reply on HN