Earlier quoted context omitted.
Your claim here is that a browser vendor could somehow fork the DNS and use its own .COM? Explain how that could possibly work.
Anyone can fork DNS. Its just a (name, key) map. As long as its done with enough consensus , it can be done. Mismanagement of .com is serious enough to demand that kind of change. Lets say .com gets mismanaged. Community is infurious. firefox/chrome/etc demands that . remap .com to new more trustable entity. If . does not. firefox/chrome/etc then remap . to new more trustable entity, because .com must be as trustable…
A DNS hijacking wave is targeting companies at an almost unprecedented scale
101–104 of 104 posts
Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale
#102Earlier quoted context omitted.
Anyone can fork DNS. Its just a (name, key) map. As long as its done with enough consensus , it can be done. Mismanagement of .com is serious enough to demand that kind of change. Lets say .com gets mismanaged. Community is infurious. firefox/chrome/etc demands that . remap .com to new more trustable entity. If . does not. firefox/chrome/etc then remap . to new more trustable entity, because .com must be as trustable…
It sounds like what you’re proposing is for browser vendors to, in unison, overthrow IANA and the related organizations and stage a coup where they start running their own DNS root authority. And then claiming that this would happen without impact to end users / owners-of-individual-domains.
Ultimately its about deciding who gets to own "x.y.z" string brand globally/contextlessly. World obviously need a single naming system. Either that or expect to have multiple owners to "google.com".
My suggestions are required otherwise why would someone build a global brand if ownership is not safe or guarnteed enough. Future is way more chaotic. Without crypto, a global naming system is not going to survive.
Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale
#103Earlier quoted context omitted.
It sounds like what you’re proposing is for browser vendors to, in unison, overthrow IANA and the related organizations and stage a coup where they start running their own DNS root authority. And then claiming that this would happen without impact to end users / owners-of-individual-domains.
Browser vendors (specifically all DNS users) have the option. They can do it, if IANA fails at the job of being a dnsroot. Disruption is inversely proportional to consensus. If everyone do it, there is no disruption. Some disruption is unavoidable. Its fair price to pay for stable and solid global naming system. Ultimately its about deciding who gets to own "x.y.z" string brand globally/contextlessly. World obviously…
Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale
#104Earlier quoted context omitted.
Yeah, yeah. So many on HN has this mindset. Criminals just whip up credit cards like it's nothing. They don't. It's noisy to use some grandma's credit card to buy a cert for buttsnstuff.ca when she donates to her local church five times a month. Almost all criminals are fucking dumb or even if they're smart they fuck up before they're good and land themselves in jail. Like at least 98% of them. HTTPS is a tire fire.…
how does let's encrypt increase the risk for anyone?
I've worked on multiple projects with credit card fraud. I've helped the Canadian government with both cybercrime and machine learning. When I say 98% of criminals are dumb, I really fucking mean it. Not everyone is USG. Most governments are worse-resourced than your run-of-the-mill startup. But people don't want to hear that scriptable HTTPS has downsides and people that are in positions that come with social cache rarely listen. They end up becoming the next generation of people with blinders on. I helped with projects that threw over a dozen people in jail. We got them on two things: IP addresses and financial transactions. Let's Encrypt takes away one possible way we could have gotten them. But people on HN are so deluded about what actual crime looks like.
You know how the vast majority of programmers are these dumb PHP coders that cobble together a Wordpress site? Crime is the same thing only worse. They have no fucking clue what they're doing. They bruteforce passwords and use exploits that target long-out-of-day vulns.