Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

51–60 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#51
post #49
post #24

I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.

With the current system, they can just seize the domain and get a certificate for it.

No. Seizing the domain does not help them if millions of browsers have the correct certificate pinned.

Meanwhile: we're all pretty unhappy that the USG does just seize domains. How can it possibly be reasonable for us to support a forklift upgrade of a core protocol that burns that capability permanently and cryptographically into the core of the Internet?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#52
post #46

Earlier quoted context omitted.

I don't understand your question. If the government can't subvert CAs, DNSSEC is pointless; let's all just rely on the CAs. It can subvert them. Now, what problem is DNSSEC solving?

I'm just trying to understand this attack that you implied.

Yes: assume one of the thousands of CAs you trust has been compromised by NSA.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#53
post #44
post #42

Earlier quoted context omitted.

How does having a new super-CA controlled by the NSA impede key pinning and certificate transparency? I agree that CAs + DANE is just as shitty or shitter than CAs. But: a) In the event DANE replaced the CA system, one super-CA controlled by the NSA is better than 300 CAs essentially controlled by 50 different governments including the NSA. b) Nobody's making you use DANE. Signed DNS records are an improvement over t…

No. (a) is wrong. The difference between DNSSEC's government-controlled super CA and a normal TLS CA is that when Google spots a normal TLS CA misbehaving because of an alert from a broken pin or CT log, it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it. Both of these things have happened and will keep happening. Google cannot do that to .COM or .IO. If the governmen…

> it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it

None of which prevents it from happening again with another one of the 300 CAs whenever another government gets antsy.

> If the government-controlled super-CA that runs .COM misbehaves, we have no recourse.

As a westerner I trust the super-CA that runs .COM 1000x more than some random CA in China or Iran or whatever. But even that's beside the point. If they abused their trust (which would be caught by CT) the whole system would collapse because, like you said, you can't shitcan .COM. Everyone would move to keypinning and/or a decentralized blockchain-based DNS solution and we would gain real security.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#54
This is the fourth time in the last 30 days I have seen some blog post about DNSSEC on the front page. Three overtly pushing Cloudflare DNSSEC and one about email and DNSSEC written by a Cloudflare employee.

But still no discussion of cache poisoning.

So if a user runs their own personal cache bound to the loopback do they need DNSSEC?

What if they run their own root?

What if they have local copies of all the zones they need?

DNSSEC gives control to untrusted third parties to periodically determine what is and what is not a "valid" domain name.

What are the protections against abuse of this control?

I would not call DNSSEC "secure DNS". I would call it "validated DNS".

The question is who is doing the "validation"?

And why should we as users trust them more than the endpoint we're trying to reach?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#55
post #24

I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.

It reminds me of when I registered r33t.org in the 90s. We couldn't register .com at first because we weren't incorporated.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#56
post #44
post #42

Earlier quoted context omitted.

How does having a new super-CA controlled by the NSA impede key pinning and certificate transparency? I agree that CAs + DANE is just as shitty or shitter than CAs. But: a) In the event DANE replaced the CA system, one super-CA controlled by the NSA is better than 300 CAs essentially controlled by 50 different governments including the NSA. b) Nobody's making you use DANE. Signed DNS records are an improvement over t…

No. (a) is wrong. The difference between DNSSEC's government-controlled super CA and a normal TLS CA is that when Google spots a normal TLS CA misbehaving because of an alert from a broken pin or CT log, it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it. Both of these things have happened and will keep happening. Google cannot do that to .COM or .IO. If the governmen…

reposting a comment:

What do you think would happen under a DNSSEC-DANE TLS world if that started being detected via key pinning/CT ?

There is just no way the NSA is going to risk it except in very very specific circumstances they can easily control, (exactly the same situation as HPKP) because, they too will be forever burned just like an ssl CA would, except now they cant just switch to one of hundreds of other CAs, they have burned the root keys to a tld. This will be obvious, this will be screamed about from the rooftops, the key will be rotated + a ton greater scrutiny applied to the process.

Its not like browsers and other people pinning certs are just going to shrug their shoulders and say "aw shucks, i guess we wont worry about it"

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#57
post #53
post #44

Earlier quoted context omitted.

No. (a) is wrong. The difference between DNSSEC's government-controlled super CA and a normal TLS CA is that when Google spots a normal TLS CA misbehaving because of an alert from a broken pin or CT log, it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it. Both of these things have happened and will keep happening. Google cannot do that to .COM or .IO. If the governmen…

> it can shitcan the CA, either evicting it from the trust store or placing onerous restrictions on it None of which prevents it from happening again with another one of the 300 CAs whenever another government gets antsy. > If the government-controlled super-CA that runs .COM misbehaves, we have no recourse. As a westerner I trust the super-CA that runs .COM 1000x more than some random CA in China or Iran or whatever…

One thing I love about DNSSEC threads is that I get to join the anti-NSA faction on HN. Unlike you, I do not trust the giant corporation that controls .COM under charter from the US Government.

The USG has repeatedly abused its trust, often directly with respect to .COM. The Internet has not fled .COM.

The idea that we would deploy a forklift upgrade of a core protocol, at immense expense (look at Cloudflare's own marketing material!), ostensibly to improve security but in reality to put ourselves in the position of "fleeing .COM IF the US Government abuses it trust", boggles my mind.

The problem DNSSEC purports to solve is not cryptographically hard. DNSSEC made it hard because it was designed in 1995, at a time when designers felt it would be implausible for DNS servers to sign records.

We are talking about deploying this fiasco of a protocol with all its compromises purely because of the momentum of a 21+ year long standardization effort. Once we deploy it, any notion of solving the problem correctly dies. That's a terrible, terrible mistake.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#58
post #3

Does this seem ironic to anyone else considering CloudFlares SSL offering essentially is a MITM attack?

How is Cloudflare SSL a MITM attack ? Obviously, they're in the middle, but you have to trust someone .

In this case, you don't. You can terminate SSL on your own machine, where you are actually running the service/site.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#59
post #16
post #3

Does this seem ironic to anyone else considering CloudFlares SSL offering essentially is a MITM attack?

The essense of "MITM" isn't the Middle but the fact that the Man is unauthorized , Eve to Alice and Bob. If Alice and Bob agree to put CloudFlare (oh, look, the C already works!) in between them, there's a Middle but there's no [unauthorized] Man. SSL's purpose isn't to create some sort of quasi-mythical "direct connection" between Alice and Bob, it's just removing the general Internet as a vector for many attacks. A…

"...certainly not a magic invocation that casts the spell of Security +1 across the entire communication..."

I appreciate the whole post, but this is such a wonderfully geeky turn of phrase that I have to acknowledge it!

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#60
post #52

Earlier quoted context omitted.

I'm just trying to understand this attack that you implied.

Yes: assume one of the thousands of CAs you trust has been compromised by NSA.

Okay, so this is what happens:

1. Evil NSA compromises CA in BFE

2. Evil NSA subverts DNSSEC for COM to publish a bad CA certificate

3. Some combination of Google Certificate Transparency + HPKP discovers this, the CA in BFE gets removed from browsers

If your point is "DNSSEC is pointless", OK. But it sounds like you're saying it makes us less secure. I'm just trying to figure out how that could even be.

Post reply on HN