Live data from Hacker News

A DNS hijacking wave is targeting companies at an almost unprecedented scale

arstechnica.com

51–60 of 104 posts

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#51
post #45

Earlier quoted context omitted.

No. You have to trust all the CAs , and the governments that control the DNS. https://www.imperialviolet.org/2015/01/17/notdane.html

> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority tha…

If browsers start mapping cert trust to something besides the DNS roots... it’s not DNSSEC, it’s something else entirely, it’s “our current system, maybe with some slight tweaks”

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#52
post #49

Earlier quoted context omitted.

You have to trust somone under DNS. The only trustless naming system I can think of is over a PoWChain (eg example.btc). Still you have 3 choices in DNSSEC/DANE, - get a .xxx, trust dnsroot. - get a .xxx (when .xxx is as easy to register as xxx.com), trust dnsroot. - pick one tld out 1000s and get xxx.ttt, and trust ttt and dnsroot.

I’ve got those choices if I use DNSSEC for my trust, correct. Or I use the existing system, where if a CA misbehaves, we boot them out of the browser trust stores and site operators don’t have to change anything.

Except there has to be a crypto proof why Google owns google.com not me. That means we need to secure dns. Then why need CAs at all ? Whats the point ?

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#53
post #51

Earlier quoted context omitted.

> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority tha…

If browsers start mapping cert trust to something besides the DNS roots... it’s not DNSSEC, it’s something else entirely, it’s “our current system, maybe with some slight tweaks”

I am not suggesting every client do their own mapping, that is not a naming system at all. There has to be very large consenus for a naming system to be effective. I just pointed that out to show that dns is not under any gov control. Its under a control of an entity that can be punished.

However who gets to have dnsroot is just a value of a config in DNSSEC. The value itself should not be used to criticize DNSSEC cause its changeable.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#54
post #45

Earlier quoted context omitted.

No. You have to trust all the CAs , and the governments that control the DNS. https://www.imperialviolet.org/2015/01/17/notdane.html

> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority tha…

The linked article is about why you can’t simply trust the DNS roots, even if you were naive enough to want to.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#55
post #49

Earlier quoted context omitted.

I’ve got those choices if I use DNSSEC for my trust, correct. Or I use the existing system, where if a CA misbehaves, we boot them out of the browser trust stores and site operators don’t have to change anything.

Except there has to be a crypto proof why Google owns google.com not me. That means we need to secure dns. Then why need CAs at all ? Whats the point ?

A group of certifying singers that aren’t directly controlled by the United States Government is the obvious reason.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#56
post #55

Earlier quoted context omitted.

Except there has to be a crypto proof why Google owns google.com not me. That means we need to secure dns. Then why need CAs at all ? Whats the point ?

A group of certifying singers that aren’t directly controlled by the United States Government is the obvious reason.

Current: Google need to watch all CAs.

DNSSEC: Google need to watch .com and dnsroot.

Which one is better ?

----

(I am ratelimited so posting here rather than reply to the child post by tptacek https://news.ycombinator.com/item?id=18889809)

Of course they can. There is literally no legal or otherwise difference between Verisign and .com. Chrome can do whatever it want, cause its Google's browser not .com's.

In case when .xxx becomes dishonest, you can just move to your own gtld or .more-trustable tld. In current system, there is no concept of ditching a CA. If a CA decided to missmap a name and you are too small, you are fked.

> it’s actually 1, or 1 AND 2

No you can have DNSSEC without CAs. I have explained that already without changing much of the tls. Basically example.com DNSSEC key become CA for example.com. example.com then would create a tls cert in the usual way. No pain.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#57
post #55

Earlier quoted context omitted.

A group of certifying singers that aren’t directly controlled by the United States Government is the obvious reason.

Current: Google need to watch all CAs. DNSSEC: Google need to watch .com and dnsroot. Which one is better ? ---- (I am ratelimited so posting here rather than reply to the child post by tptacek https://news.ycombinator.com/item?id=18889809 ) Of course they can. There is literally no legal or otherwise difference between Verisign and .com. Chrome can do whatever it want, cause its Google's browser not .com's. In case…

The former, for several reasons, among them the fact that those actually aren’t the options (it’s actually 1, or 1 AND 2), and the fact that Google can’t end .com they way they did Verisign.

But feel free to ask the relevant team at Google, who will give you the same answer.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#58
post #51

Earlier quoted context omitted.

If browsers start mapping cert trust to something besides the DNS roots... it’s not DNSSEC, it’s something else entirely, it’s “our current system, maybe with some slight tweaks”

I am not suggesting every client do their own mapping, that is not a naming system at all. There has to be very large consenus for a naming system to be effective. I just pointed that out to show that dns is not under any gov control. Its under a control of an entity that can be punished. However who gets to have dnsroot is just a value of a config in DNSSEC. The value itself should not be used to criticize DNSSEC ca…

How do you punish .com if they misbehave? Move every site off .com?

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#59
post #55

Earlier quoted context omitted.

A group of certifying singers that aren’t directly controlled by the United States Government is the obvious reason.

Current: Google need to watch all CAs. DNSSEC: Google need to watch .com and dnsroot. Which one is better ? ---- (I am ratelimited so posting here rather than reply to the child post by tptacek https://news.ycombinator.com/item?id=18889809 ) Of course they can. There is literally no legal or otherwise difference between Verisign and .com. Chrome can do whatever it want, cause its Google's browser not .com's. In case…

“You can just move to your own ” isn’t even remotely plausible. Any site with worthwhile traffic isn’t going to just forklift to a new TLD and convince all their users to switch over. Imagine if .com was considered untrustworthy and suddenly every user in the US had to use google.othertld, facebook.othertld, etc.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#60
post #47

If an attacker can spoof your DNS records (or if they can simply man in the middle the connection between your server and the internet), then they can generate valid Let’s Encrypt certificates. If I had the time or inclination, I’d write a transparent https gateway that used let’s encrypt to man-in-the-middle http and https connections to servers behind it. You could imagine deploying something like that on the edge…

For the MTM scenario, how would you convince letsencrypt’s CA to issue you a cert for any domain? Don’t you need to complete the challenge in order for the CA to issue you a cert?
Post reply on HN