Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

101–110 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#101
post #92
post #71

Earlier quoted context omitted.

The nice thing about DNSSEC and the ccTLDs is that you can pick what country you trust. So you can get a domain in a country that is compatible with what you are trying to do. Of course, with domain validated SSL certificates, you also have to trust DNS completely, because anyone who controls your domain can get a cert for that domain.

I hear this a lot too and it blows my mind. How is it a nice thing about DNSSEC that your choice of domain names will have a major impact on your security? That seems like a straightforwardly bad thing.

That's a good thing. Because the same applies to just about anything else. Where your servers are, who announces your IP space. Or outside the internet, where you are living, where your company is registered, where you do business.

The current CA system is the odd one out. Any CA in any country can create a cert for your domain that is recognized everywhere.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#102
post #87
post #84

Earlier quoted context omitted.

How is that worse? You already have US government in your CAs, for example Federal Common Policy CA. At least with DNSSEC only the organization that owns the TLD can issue certificates. With CA system in the browsers a country you might never heard of can issue certificate for google.com (which already happened). Yes, the danger could be root certificate is managed by a single organization, but this can be easily sol…

You don't have to trust the government CAs. A specific CA isn't part of SSL protocol.

But it is an essential part of it and those certificates are provided to you upstream.

Disabling them is discouraged, if you disable them you might start having issues (for example I disabled CA's on my Android phone) then noticed that many of my apps started crashing or had weird issues without providing meaningless messages.

If you disable them chances are that new version of the software will enable them back. You're essentially forced to live with them.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#103
post #96

Earlier quoted context omitted.

The whole concept of certificates in the first place relies on your ability to keep the private key secret. You know what you really have no recourse to? The police coming when you are asleep and "interrogating" you until you give them access to the key.

I feel like I'm trying to give you detailed technical answers, and that your responses are mostly about abstractions. I'm not thinking about DNSSEC abstractly. I am concerned with its specifics, which I have studied for a long time and am convinced will harm the Internet. That's the nicest way I can say that your response to what I just said seems like a non sequitur. I just explained what I meant by recourse. I'm so…

You can make your DNS server ignore root certificate and use anchors stored locally for specific TLD.

If then you contact a TLD that's owned by 3rd party you essentially trusting whoever owns that TLD. For example .google is owned by Google, so whatever is under it is under their full control.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#104
post #103
post #96

Earlier quoted context omitted.

I feel like I'm trying to give you detailed technical answers, and that your responses are mostly about abstractions. I'm not thinking about DNSSEC abstractly. I am concerned with its specifics, which I have studied for a long time and am convinced will harm the Internet. That's the nicest way I can say that your response to what I just said seems like a non sequitur. I just explained what I meant by recourse. I'm so…

You can make your DNS server ignore root certificate and use anchors stored locally for specific TLD. If then you contact a TLD that's owned by 3rd party you essentially trusting whoever owns that TLD. For example .google is owned by Google, so whatever is under it is under their full control.

"DNSSEC is fine, as long as we all give up on .COM". Ok.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#105
post #96

Earlier quoted context omitted.

The whole concept of certificates in the first place relies on your ability to keep the private key secret. You know what you really have no recourse to? The police coming when you are asleep and "interrogating" you until you give them access to the key.

I feel like I'm trying to give you detailed technical answers, and that your responses are mostly about abstractions. I'm not thinking about DNSSEC abstractly. I am concerned with its specifics, which I have studied for a long time and am convinced will harm the Internet. That's the nicest way I can say that your response to what I just said seems like a non sequitur. I just explained what I meant by recourse. I'm so…

One of the flaws about talking with an overloaded term like "security". If even abstractly, something does not work, what's the point of arguing about its technical details?

As you said before, DNSSEC is fine if you concede .com to the US government. This has already happened, we're just putting it in writing.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#106
post #96

Earlier quoted context omitted.

I feel like I'm trying to give you detailed technical answers, and that your responses are mostly about abstractions. I'm not thinking about DNSSEC abstractly. I am concerned with its specifics, which I have studied for a long time and am convinced will harm the Internet. That's the nicest way I can say that your response to what I just said seems like a non sequitur. I just explained what I meant by recourse. I'm so…

One of the flaws about talking with an overloaded term like "security". If even abstractly, something does not work, what's the point of arguing about its technical details? As you said before, DNSSEC is fine if you concede .com to the US government. This has already happened, we're just putting it in writing.

No, we have not already conceded TLS keys for sites in .COM to the USG.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#107
post #89

Earlier quoted context omitted.

And how exactly do you think rotating a TLD key will help if it's obvious that TLD will just give the new key to the NSA anyway?

the same way it can help in the case of the CA, parties like Google will set strict standards + see them compiled with or DANE etc will be ignored from the suspect TLDs.

What does it mean to "set strict standards" on .COM? Google can eliminate whole CAs, or scope them down to only a subset of names. It can't do that with .COM.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#108
post #30

Earlier quoted context omitted.

That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.

"DNSSEC: everything will be fine as long as everyone moves to domains in Bouvet Island's .BV. Brought to you by Cloudflare."

.bv is a great TLD choice if you want to give many women visiting your website a subtle negative connotation.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#109

Earlier quoted context omitted.

the same way it can help in the case of the CA, parties like Google will set strict standards + see them compiled with or DANE etc will be ignored from the suspect TLDs.

What does it mean to "set strict standards" on .COM? Google can eliminate whole CAs, or scope them down to only a subset of names. It can't do that with .COM.

it can however refuse to allow DANE to be used on .COM/other TLDs + apply immense political pressure.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#110

Earlier quoted context omitted.

What does it mean to "set strict standards" on .COM? Google can eliminate whole CAs, or scope them down to only a subset of names. It can't do that with .COM.

it can however refuse to allow DANE to be used on .COM/other TLDs + apply immense political pressure.

If you're not going to allow DANE on .COM, what's the point?
Post reply on HN