Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

91–100 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#91
post #77

Earlier quoted context omitted.

I don't know. Why don't you ask Moxie Marlinspike, who frequently comments on HN, what he thinks of DNSSEC?

His comments are noted. They don't seem to include, "we're shutting down Convergence and Tack now that CloudFlare have rolled out DNSSEC." Can you cite a technical reason why DNSSEC inhibits development of possibly more worthy security techniques?

I used to work in DNS security. DNSSEC is a really bad idea. It blocked us from doing really innovative work that would have protected people.

Lots of really smart folks like tptacek and djb oppose it too. But even we can't stand in the way of millions in NSF dollars and a mission statement.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#92
post #71
post #45

Earlier quoted context omitted.

And to get that feature all you have to do is trust that the government that controls your TLD isn't going to fuck you. Because it's not like the USG would ever tamper with the DNS to further a policy goal, right? http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...

The nice thing about DNSSEC and the ccTLDs is that you can pick what country you trust. So you can get a domain in a country that is compatible with what you are trying to do. Of course, with domain validated SSL certificates, you also have to trust DNS completely, because anyone who controls your domain can get a cert for that domain.

I hear this a lot too and it blows my mind. How is it a nice thing about DNSSEC that your choice of domain names will have a major impact on your security? That seems like a straightforwardly bad thing.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#93
post #86

Earlier quoted context omitted.

That's the trust that government always requires. Being on the internet doesn't change the fact that the point of government is a monopoly on authorized use of force. They can always just send men with guns to your office, DNSSEC or no. If you don't trust your government not to abuse their power, that's not a problem that Cloudflare can help you with.

So you're excuse is that it's insecure but only to the government and you should be okay with systems insecure to the government? That's a sad state affairs if that's where the security community is.

The security community is not in any one place.

The only thing even theoretically secure to a government is another government, and reality almost always falls short of that. That has nothing to do with technology, just politics.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#94
post #83

Earlier quoted context omitted.

His comments are noted. They don't seem to include, "we're shutting down Convergence and Tack now that CloudFlare have rolled out DNSSEC." Can you cite a technical reason why DNSSEC inhibits development of possibly more worthy security techniques?

That's not really my argument. DNSSEC will kill any meaningful future work in DNS security , but like I keep saying, I'm not anti-DNSSEC because I'm pro-DNSCurve; I just think DNS security is a stupid problem. Draw a layer diagram of TCP/IP up through HTTPS. Somewhere on that diagram you have to draw a line and say "below this line we're not going to attempt cryptographic security". That's not a new insight; it's bas…

Without the proposition "Once we deploy it, any notion of solving the problem correctly dies", which you seem to repudiate here, much of the sound and fury on HN in recent days would evaporate.

People doing dumb shit on the internet is typically not a problem for me, so while the end-to-end argument suffices to dismiss DNSSEC as worthy of investigation, I remain confused by all the attention drawn to this. If it's all a CloudFlare marketing stunt, has no one heard of the Streisand Effect? If it's all an NSA email-reading effort, why don't they just keep reading our email in the same fashion they already do? Confusing...

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#95
post #88

Earlier quoted context omitted.

They already have the ability. Since that can't be revoked, might as well make it transparent and grant them the authority to match it. It's certainly better than the current CA system.

I know a lot of people seem to think that, but that's just not right. You can pin a certificate with X.509 CA TLS, and you can theoretically pin a certificate against DNSSEC/DANE (no browser does and it's unlikely they ever will; browsers flirted with DNSSEC a few years ago and that code has been withdrawn). But when you pin an X.509 CA cert, you can also punish CAs that issue fraudulent CAs that break pins. This has…

The whole concept of certificates in the first place relies on your ability to keep the private key secret. You know what you really have no recourse to? The police coming when you are asleep and "interrogating" you until you give them access to the key.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#96
post #88

Earlier quoted context omitted.

I know a lot of people seem to think that, but that's just not right. You can pin a certificate with X.509 CA TLS, and you can theoretically pin a certificate against DNSSEC/DANE (no browser does and it's unlikely they ever will; browsers flirted with DNSSEC a few years ago and that code has been withdrawn). But when you pin an X.509 CA cert, you can also punish CAs that issue fraudulent CAs that break pins. This has…

The whole concept of certificates in the first place relies on your ability to keep the private key secret. You know what you really have no recourse to? The police coming when you are asleep and "interrogating" you until you give them access to the key.

I feel like I'm trying to give you detailed technical answers, and that your responses are mostly about abstractions. I'm not thinking about DNSSEC abstractly. I am concerned with its specifics, which I have studied for a long time and am convinced will harm the Internet.

That's the nicest way I can say that your response to what I just said seems like a non sequitur. I just explained what I meant by recourse. I'm sorry, but I think you're wrong.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#97
post #83

Earlier quoted context omitted.

That's not really my argument. DNSSEC will kill any meaningful future work in DNS security , but like I keep saying, I'm not anti-DNSSEC because I'm pro-DNSCurve; I just think DNS security is a stupid problem. Draw a layer diagram of TCP/IP up through HTTPS. Somewhere on that diagram you have to draw a line and say "below this line we're not going to attempt cryptographic security". That's not a new insight; it's bas…

Without the proposition "Once we deploy it, any notion of solving the problem correctly dies", which you seem to repudiate here, much of the sound and fury on HN in recent days would evaporate. People doing dumb shit on the internet is typically not a problem for me, so while the end-to-end argument suffices to dismiss DNSSEC as worthy of investigation, I remain confused by all the attention drawn to this. If it's al…

I vigorously disagree that the "sound and fury" on HN is about DNSSEC sucking all the oxygen out of the DNS security problem. It is on its face a PKI that gives control over .COM keys to the NSA.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#98
post #91

Earlier quoted context omitted.

His comments are noted. They don't seem to include, "we're shutting down Convergence and Tack now that CloudFlare have rolled out DNSSEC." Can you cite a technical reason why DNSSEC inhibits development of possibly more worthy security techniques?

I used to work in DNS security. DNSSEC is a really bad idea. It blocked us from doing really innovative work that would have protected people. Lots of really smart folks like tptacek and djb oppose it too. But even we can't stand in the way of millions in NSF dollars and a mission statement.

I can give a specific example of that happening:

The "Kaminsky Attack" from 2008 was an extension of a well known attack from the late 1990s (Kaminsky's innovation was to combine the two best-known attacks from the 90s: request ID prediction and authority record poisoning).

When he announced it, Kaminsky's attack impacted BIND (the de facto standard server) but not djbdns. That's because djbdns randomized ports and request IDs, making the attack difficult (not impossible, but not practical). Djbdns started out randomized that way.

Back in the 1990s, when request ID attacks were first being demonstrated, it was suggested on NANOG that BIND randomize ports as well. IIRC, Vixie even claimed to have performance numbers for a "scoreboarding resolver" that used randomization. But he objected to the deployment of that software, because the "right" solution was DNSSEC.

(I was on NANOG at the time because I had written exploit code for both sets of problems).

Fast forward a decade and Kaminsky has "broken the Internet", forcing BIND to finally fully randomize (a countermeasure that more or less killed his attack). The irony is: Kaminsky's attack was seized on as a reason to deploy DNSSEC!

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#99

DNSCurve and DNSCrypt are the better solutions for slightly different problems that I think we should be pushing.

Come work at CloudFlare! Let's get working on that.

It's good to see CloudFlare continuing to embrace security as it evolves. I saw the AMA Matthew Prince did where he said he was concerned about ICANN giving control to the UN, which is a bigger deal than most admit, and he also said he was against regionalization of the net, another issue that doesn't get enough attention. Keep up the good work.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#100
post #89

Earlier quoted context omitted.

reposting a comment: What do you think would happen under a DNSSEC-DANE TLS world if that started being detected via key pinning/CT ? There is just no way the NSA is going to risk it except in very very specific circumstances they can easily control, (exactly the same situation as HPKP) because, they too will be forever burned just like an ssl CA would, except now they cant just switch to one of hundreds of other CAs…

And how exactly do you think rotating a TLD key will help if it's obvious that TLD will just give the new key to the NSA anyway?

the same way it can help in the case of the CA, parties like Google will set strict standards + see them compiled with or DANE etc will be ignored from the suspect TLDs.
Post reply on HN