Live data from Hacker News

A DNS hijacking wave is targeting companies at an almost unprecedented scale

arstechnica.com

61–70 of 104 posts

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#61
post #58

Earlier quoted context omitted.

I am not suggesting every client do their own mapping, that is not a naming system at all. There has to be very large consenus for a naming system to be effective. I just pointed that out to show that dns is not under any gov control. Its under a control of an entity that can be punished. However who gets to have dnsroot is just a value of a config in DNSSEC. The value itself should not be used to criticize DNSSEC ca…

How do you punish .com if they misbehave? Move every site off .com?

No. You just map .com to another key with an agreement that new .com owner pre signs and map existing .com subs the right way. An unaware xxx.com does not need to do anything. As long as its done publically with a bang and enough consensus, disruption should be minimal.

Again this is unavoidable in any system that need trust. Thats why I like PoW DNS.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#62
post #17
post #7

Note that these attacks involve compromised accounts with authority servers , so despite being the most visible and impactful DNS attacks of the last few years, DNSSEC would have done little to defend against them; in fact, even in the DNSSEC fantasy-world where DANE replaces X.509 CAs, these attackers would still have accomplished their goals.

after reading the headline I immediately thought of "14 DNS Nerds Don't Control the Internet" [0]. [0] https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont-con...

That article is peddling bullshit.

Yes, DNSSEC is not adopted. But what the intention with it is to stop people hijacking DNS requests (re-routing then to rogue servers for instance,) and then returning spurious answers.

That’s a relatively simple attack, and it can have fairly serious reprocussions. Just return an A record for the domain and host straight HTTP for example. Or re-divert emails with MX records. Publish fake CAA records to bypass that safety lock if you want to supply a cert obtained elsewhere.

The stuff about the US Govt controlling sites is the most facetious of all. As the original (non) story above shows, controlling the DNS is all you need to control a site in the X.509 world. Extended validation is a joke, controlling the domain is the only barrier to getting TLS certs issued for any domain.

We implicitly need to trust the root DNS. That’s a given. So why couldn’t it be the root of trust for secure browsing? Browsers trust something like 1500 CAs out of the box these days, is it really better to create a system where that many orgs need to be honest, and not get hacked, to be effective?

To claim that the current system, with no way to for people know the DNS answers they receive are valid, poses no security risk, is extremely foolish.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#63
post #17

Earlier quoted context omitted.

after reading the headline I immediately thought of "14 DNS Nerds Don't Control the Internet" [0]. [0] https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont-con...

Much better than (CA0 || CA1 || ... ). All it takes is one CA out of 10s of independent CAs to misbehave to insecure whole tls. In DNSSEC/DANE, world only has to watch one entity rather than 10s of entities.

There are about 1500 entities in the X.509 game, not 10s.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#64
post #45

Earlier quoted context omitted.

Much better than (CA0 || CA1 || ... ). All it takes is one CA out of 10s of independent CAs to misbehave to insecure whole tls. In DNSSEC/DANE, world only has to watch one entity rather than 10s of entities.

No. You have to trust all the CAs , and the governments that control the DNS. https://www.imperialviolet.org/2015/01/17/notdane.html

That’s not pure DANE being discussed by a hybrid in which CAs are still playing a role.

In pure DANE you need only trust the DNS root.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#65
post #54

Earlier quoted context omitted.

> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority tha…

The linked article is about why you can’t simply trust the DNS roots, even if you were naive enough to want to.

If you can’t trust them then the whole thing crumbles anyway.

All you need to obtain valid TLS certs for any domain is to make a CA think you control the domain. So the CA’s trust in the DNS root is already functioning as the basis of X.509.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#66
post #42

Earlier quoted context omitted.

Much better than (CA0 || CA1 || ... ). All it takes is one CA out of 10s of independent CAs to misbehave to insecure whole tls. In DNSSEC/DANE, world only has to watch one entity rather than 10s of entities.

Except if that one entity misbehaves, even if you catch them, you can't do anything about it, because they own the TLD.

Yeah but because they own the TLD they can get X.509 certs issued for any domain under it, because controlling the domain is the only check CAs really perform before issuing a cert for a domain.

The DNS is already acting as the root of trust for X.509. X.509 does not make the scenario of a rogue TLD operator any different.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#67
post #49

Earlier quoted context omitted.

You have to trust somone under DNS. The only trustless naming system I can think of is over a PoWChain (eg example.btc). Still you have 3 choices in DNSSEC/DANE, - get a .xxx, trust dnsroot. - get a .xxx (when .xxx is as easy to register as xxx.com), trust dnsroot. - pick one tld out 1000s and get xxx.ttt, and trust ttt and dnsroot.

I’ve got those choices if I use DNSSEC for my trust, correct. Or I use the existing system, where if a CA misbehaves, we boot them out of the browser trust stores and site operators don’t have to change anything.

The CAs, for the most part, only require you prove you control a domain to issue a cert for it.

So you’re already trusting the DNS, whether protected with DNSSEC or not, in the existing system.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#68
post #59

Earlier quoted context omitted.

Current: Google need to watch all CAs. DNSSEC: Google need to watch .com and dnsroot. Which one is better ? ---- (I am ratelimited so posting here rather than reply to the child post by tptacek https://news.ycombinator.com/item?id=18889809 ) Of course they can. There is literally no legal or otherwise difference between Verisign and .com. Chrome can do whatever it want, cause its Google's browser not .com's. In case…

“You can just move to your own ” isn’t even remotely plausible. Any site with worthwhile traffic isn’t going to just forklift to a new TLD and convince all their users to switch over. Imagine if .com was considered untrustworthy and suddenly every user in the US had to use google.othertld, facebook.othertld, etc.

Yeah but if .com is untrustworthy then the game is up.

The operator of .com can use their control over it to get a valid TLS cert issued by any number of CAs.

So the situation is no different currently, trust in the DNS is essential.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#69
post #47

If an attacker can spoof your DNS records (or if they can simply man in the middle the connection between your server and the internet), then they can generate valid Let’s Encrypt certificates. If I had the time or inclination, I’d write a transparent https gateway that used let’s encrypt to man-in-the-middle http and https connections to servers behind it. You could imagine deploying something like that on the edge…

For the MTM scenario, how would you convince letsencrypt’s CA to issue you a cert for any domain? Don’t you need to complete the challenge in order for the CA to issue you a cert?

You’d have to somehow redirect / spoof DNS responses to Let’s Encrypt to fool them and make it look like you passed the challenge.

Not trivial, but far from impossible for as long as the world maintains that securing the DNS is pointless.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#70
post #35

This is the problem with quickie SSL cert issuance from "Let's Encrypt". If it took 10 days of consistent domain resolution to get an SSL cert, this wouldn't be happening.

The attack is based on compromising control of the victim’s domain.

What’s to stop someone in control of a domain putting records up for 10 days? It’d still happen, just be a delay between compromising the domain and getting the cert is all.

Post reply on HN