Live data from Hacker News

DNSSEC KSK rollover breaks DNS resolution for .nz domains

status.internetnz.nz

151–160 of 181 posts

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#151

Earlier quoted context omitted.

For a state like the US, with it's laws and history on surveillance. I assume PKI has been compromised. I don't check or audit my CA's and don't think most people do either. Wouldn't be surprised if more than one of these has been compromised in some fashion already. It only takes one and there's plenty to target. The next thing you'd need is a mitm attack and again that's entirely possible for a nation state to pull…

> I don't check or audit my CA's and don't think most people do either. The people responsible for running the root stores do. And when CAs screw up, they are nuked from orbit--this has happened a few times. And they can be proactive: when Kazakhstan announced they would require all TLS connections to be MITM'd, the browsers promptly added the MITM certificate to the root store with the explicit distrust bit set, mea…

> The people responsible for running the root stores do. And when CAs screw up, they are nuked from orbit--this has happened a few times

The CAs that got the boot were detected because they issued certificates that were obviously invalid, for example for domains like example.com (Symantec), test.com (Certinomis), or domains that didn't even exist (Camerfirma).

A CA that issues an unauthorized certificate for some random domain won't be detected unless that domain's owner is monitoring CT because no one else knows if the certificate is authorized or not.

So please do monitor CT for your domains and don't just rely on root stores and security researchers to do so.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#152
post #73

Earlier quoted context omitted.

All the CAs are required to log. You don't have to trust any of them. The premise of CT isn't that every device is watching the logs in real time, such that your set-top box is somehow using it.

Somebody has got to check the logs and report violations. Chrome does, so CT works mostly for the world wide web, because all websites want to work in Chrome. For a device like a router, if the router doesn't check the logs itself, and a global adversary compromises the TLS update channel for the router, and starts distributing malicious firmware... If the router itself doesn't report the violation, for how long migh…

I don't think firmware updates for routers is a good example. That seems more like the kind of situation where you should actually be using your own PKI.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#153
post #104

Earlier quoted context omitted.

Ok. That's an argument you can make. Now go back and make that in the first place rather than diverting everyone down an incredibly tedious demonstration of you making assertive statements that are just factually wrong. There's space to talk about what tradeoffs are reasonable here (eg, if this is something you're concerned about, you can pick a CA that's not in a hostile country, and you can enable certificate stapl…

It's the argument I made at the top: > The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and your certificate issuer. It's probably fair to say I've been a bit over assertive about CT, but it's all in the margin to me. No amount of technical complexity can turn community trust into direct trust. TLS is a community trust model and DNS…

CT trust does not in fact rely on "the community" at large taking action against bad actors. The history of CA surveillance will avail.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#154
post #148

Earlier quoted context omitted.

I'm literally just waking up right now and typing this from bed (ignore what that says about me as a person) so cut me some slack if this makes no sense and I reserve the right to come back and "clarify" what I was saying but: if Chromes see a Sectigo certificate for (say) Facebook.com with no SCTs, Google is going to notice.

Nope. If Chrome sees a certificate with no SCTs, it rejects the certificate but doesn't report it to Google. (Except possibly for telemetry.) Google doesn't care if CAs issue certificates without SCTs; in fact, some CAs routinely do so for customers which want to keep internal hostnames private. (e.g. https://docs.aws.amazon.com/acm/latest/userguide/acm-bestpra... ) SCT auditing only takes place if a certificate has…

Yep, I acknowledge this is the case. Thanks for the correction!

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#155
post #56
post #53

Earlier quoted context omitted.

At this point it feels like DNS should be given to Cloudflare or Google and let them design it from scratch. I'm only half joking.

I'm not real enthused about Google doing standards. OAuth/OAuth2 are both so half-baked that we now have OIDC built atop them to try and make it look like a consistent workable standard. Google is very enthusiastic it seems about things which force users to use Google Chrome, and very unenthusiastic about users doing anything easily from the command line because it has the notable quality of removing a place you can…

"Google is very enthusiastic it seems about things which force users to use Google Chrome, and very unenthusiastic about users doing anything easily from the command line because it has the notable quality of removing a place you can show ads."

What else would we expect from an advertising company.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#156

Earlier quoted context omitted.

Web PKI so strong that we recommend not using it for critical scenarios.. /s It's late and I maybe haven't been super constructive here, but I think when you try to write out the actual assumptions behind CT as the whole solution, you realize you've got something that mostly works assuming assuming assuming - and worse, we'll never do any better, because those assumptions are fundamental technical limits. DNSSec may…

The whole premise of your argument about set-top boxes and CT was refuted, and you've used that as evidence that you were right all along.

Do you believe CT protects set-top boxes against surveillance from nation state actors who compromise your router? Yes or no, if you don't answer, you're not engaging in good faith.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#157

Earlier quoted context omitted.

It's the argument I made at the top: > The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and your certificate issuer. It's probably fair to say I've been a bit over assertive about CT, but it's all in the margin to me. No amount of technical complexity can turn community trust into direct trust. TLS is a community trust model and DNS…

CT trust does not in fact rely on "the community" at large taking action against bad actors. The history of CA surveillance will avail.

Of course it does. CT trust relies on root programs removing bad CAs and root programs and security researchers sharing information about bad CAs with root programs. The root programs, CA, and security researchers are colloquially "the CA community".

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#158

Earlier quoted context omitted.

CT trust does not in fact rely on "the community" at large taking action against bad actors. The history of CA surveillance will avail.

Of course it does. CT trust relies on root programs removing bad CAs and root programs and security researchers sharing information about bad CAs with root programs. The root programs, CA, and security researchers are colloquially "the CA community".

This kind of handwaving summary would be more credible if it hadn't been preceded by a long thread where it was made clear you didn't understand how CT functioned, at, like, a very basic level. You entered this conversation stridently equating CT monitoring with things like revocation checking.

I'm not looking for a debate; I'm just calling out things you say that are misleading and moving on. You're welcome to dispute my callouts! I'm satisfied that the thread establishes which arguments are credible and which aren't.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#159

Earlier quoted context omitted.

The whole premise of your argument about set-top boxes and CT was refuted, and you've used that as evidence that you were right all along.

Do you believe CT protects set-top boxes against surveillance from nation state actors who compromise your router? Yes or no, if you don't answer, you're not engaging in good faith.

Nobody's ever going to continue discussing things with you when you end your comments with barbs like "if you don't answer, you're not engaging in good faith."

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#160
post #131

Earlier quoted context omitted.

By trusting certificates, you implicitly trust all CAs, not just your own.

You trust your browser's root program, not "all CAs".

That’s what a “CA” is. If someone is not in a browser’s CA list, they’re not a CA. So yes, you do trust all CAs.
Post reply on HN