Live data from Hacker News

A DNS hijacking wave is targeting companies at an almost unprecedented scale

arstechnica.com

71–80 of 104 posts

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#71
post #17

Earlier quoted context omitted.

after reading the headline I immediately thought of "14 DNS Nerds Don't Control the Internet" [0]. [0] https://sockpuppet.org/blog/2016/10/27/14-dns-nerds-dont-con...

That article is peddling bullshit. Yes, DNSSEC is not adopted. But what the intention with it is to stop people hijacking DNS requests (re-routing then to rogue servers for instance,) and then returning spurious answers. That’s a relatively simple attack, and it can have fairly serious reprocussions. Just return an A record for the domain and host straight HTTP for example. Or re-divert emails with MX records. Publis…

Here's a story about a DNS hijacking attack unprecedented in scale for which DNSSEC is powerless, and your conclusion is that DNSSEC is an important priority.

If you believe control of the DNS is straightforward without DNSSEC, and that control of the DNS is all you need to get an X.509 certificate issued, go get a GOOGLE.COM certificate misissued. Or FACEBOOK.COM. If you actually manage to do it (you won't), turn the timer on your iPhone on so we can measure how long it takes for Google to kill the CA you got it from, with no notification or further intervention from you.

We do not implicitly trust the DNS roots. In fact, it's a core feature of modern Internet security (modern since the late 1990s) that we do not trust DNS at all. It is a small faction of standards zealots, whose pet standard failed for almost 30 years to either gel or get traction in the market, who have decided that their spurned work turns out to be critical to all Internet security, and they're the ones revisiting that long-decided question.

You made this argument in, I think, 3 other places in this thread, and I'd just like to say that I put some effort into making sure my rebuttals relied on different arguments each time. Collect them all! I wrote them I think a little snarkily, but I tried to exceed the bar you set by claiming I'm "peddling bullshit".

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#72
post #45

Earlier quoted context omitted.

No. You have to trust all the CAs , and the governments that control the DNS. https://www.imperialviolet.org/2015/01/17/notdane.html

That’s not pure DANE being discussed by a hybrid in which CAs are still playing a role. In pure DANE you need only trust the DNS root.

The whole premise of AGL's article is the fact that you can't have pure DANE. Literally, "a hybrid of DANE and CAs" is just a restatement of the sentence "you have to trust all the CAs and the DNS". You haven't said anything in this comment.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#73
post #58

Earlier quoted context omitted.

How do you punish .com if they misbehave? Move every site off .com?

No. You just map .com to another key with an agreement that new .com owner pre signs and map existing .com subs the right way . An unaware xxx.com does not need to do anything. As long as its done publically with a bang and enough consensus, disruption should be minimal. Again this is unavoidable in any system that need trust. Thats why I like PoW DNS.

Who is "you"? The people we're afraid of manipulating .COM control the DNS. Google can't "map .com to another key". Their option would be to leave .COM; that is the gun DNSSEC would give to the USG to hold against Google's head.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#74
post #54

Earlier quoted context omitted.

The linked article is about why you can’t simply trust the DNS roots, even if you were naive enough to want to.

If you can’t trust them then the whole thing crumbles anyway. All you need to obtain valid TLS certs for any domain is to make a CA think you control the domain. So the CA’s trust in the DNS root is already functioning as the basis of X.509.

You manifestly can't trust them today, couldn't yesterday, or for the last 30 years, despite the rise of e-commerce and the gradual shift of all applications to the web with its domain-validated WebPKI. Google doesn't DNSSEC sign. Facebook doesn't DNSSEC sign. No major bank I've found DNSSEC signs. AT&T doesn't DNSSEC sign, nor does Verizon. Some part of Comcast does, or did, and the net effect was that DNSSEC errors broke HBO NOW on launch day for Comcast users (and only Comcast users).

Tell me more about how the whole thing crumbles away? Because I'm pretty sure I'm typing into a TEXTAREA on the real HN, and not some facsimile a DNS hacker created to fool me. The Internet seems to be working fine without the government-run PKI you're saying we have to have.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#75
post #34

Earlier quoted context omitted.

Yeah but you used to need a credit card. The barrier to entry is lower. HTTPS is a tire fire.

Your completely right, where on Earth would criminals and scammers be able to get a credit card? /s I am having a hard time understanding how more websites using https could possibly be a worse thing.

It’s even worse now that a lot of online services record your card so it will be easier for valid user to pay a service.

If your credentials are compromised, even a paying certificate is easy to get.

On a small company, the payment might be noticed. On big companies the odds are low.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#76
post #49

Earlier quoted context omitted.

I’ve got those choices if I use DNSSEC for my trust, correct. Or I use the existing system, where if a CA misbehaves, we boot them out of the browser trust stores and site operators don’t have to change anything.

The CAs, for the most part, only require you prove you control a domain to issue a cert for it. So you’re already trusting the DNS, whether protected with DNSSEC or not, in the existing system.

And yet when attackers want to misissue certs for small sites (for big sites, misissuance is detected automatically and gets CAs killed), they don't exploit vulnerabilities that DNSSEC defends against. Why is that? And given that's the case, why pursue DNSSEC?

And how is any of this, any of it all, relevant in a world where registrars can simply speak RDAP to CAs? If you believe the problem is that the Internet will (to use your turn of phrase upthread) crumble away unless we secure the DNS for domain validation, why should we forklift out the entire DNS to do so, when we can just get a small group of organizations to deploy RDAP, something they're planning on deploying anyways, and then add that to the 10 Blessed Methods?

No part of DNSSEC makes any sense.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#77
post #59

Earlier quoted context omitted.

“You can just move to your own ” isn’t even remotely plausible. Any site with worthwhile traffic isn’t going to just forklift to a new TLD and convince all their users to switch over. Imagine if .com was considered untrustworthy and suddenly every user in the US had to use google.othertld, facebook.othertld, etc.

Yeah but if .com is untrustworthy then the game is up. The operator of .com can use their control over it to get a valid TLS cert issued by any number of CAs. So the situation is no different currently, trust in the DNS is essential.

Again if that's true then the game is up, because the USG obviously controls .COM; they theatrically demonstrate that every time they take down a piracy site. But, spoiler! The game turns out not to be up.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#78
post #34

Earlier quoted context omitted.

Your completely right, where on Earth would criminals and scammers be able to get a credit card? /s I am having a hard time understanding how more websites using https could possibly be a worse thing.

Yeah, yeah. So many on HN has this mindset. Criminals just whip up credit cards like it's nothing. They don't. It's noisy to use some grandma's credit card to buy a cert for buttsnstuff.ca when she donates to her local church five times a month. Almost all criminals are fucking dumb or even if they're smart they fuck up before they're good and land themselves in jail. Like at least 98% of them. HTTPS is a tire fire.…

Criminals who hijack websites do in fact whip up credit cards "like it's nothing". A huge chunk of abuse attempts on websites that process transactions with credit cards is performed simply to bulk-verify stolen cards. Not even to buy things with the cards; just as a sort of scammer mapreduce to see which of their zillion cards work.

The idea that credit card forms are a form of defense in depth is lunacy.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#79
post #78

Earlier quoted context omitted.

Yeah, yeah. So many on HN has this mindset. Criminals just whip up credit cards like it's nothing. They don't. It's noisy to use some grandma's credit card to buy a cert for buttsnstuff.ca when she donates to her local church five times a month. Almost all criminals are fucking dumb or even if they're smart they fuck up before they're good and land themselves in jail. Like at least 98% of them. HTTPS is a tire fire.…

Criminals who hijack websites do in fact whip up credit cards "like it's nothing". A huge chunk of abuse attempts on websites that process transactions with credit cards is performed simply to bulk-verify stolen cards . Not even to buy things with the cards; just as a sort of scammer mapreduce to see which of their zillion cards work. The idea that credit card forms are a form of defense in depth is lunacy.

Interesting. Could the credit card industry take advantage of this by setting up honeypots - sites that look easily exploitable to the average crook, but that would actually provide card issuers with a list of stolen cards?

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#80

Could this be a big setback for "Let's Encrypt" since it uses DNS resolution for its own authentication instead of being a second factor?

So, the validation done by all publicly trusted Certificate Authorities has to require one of the "Ten Blessed Methods". That's what they're called, though today there are exactly nine of them.

3.2.2.4.1 and 3.2.2.4.5 are now obsolete and no longer used, method 3.2.2.4.11 is basically what happened before the "Ten Blessed Methods" and so now irrelevant.

Methods 3.2.2.4.2 through 3.2.2.4.4 are about contacting somebody based on details from WHOIS by various methods, like sending them a Fax, or giving them a phone call. This is even more laughably insecure than your average DNS setup.

Method 3.2.2.4.6 is the way most people get their first Let's Encrypt cert, and is also a popular option for lots of other bulk CAs, it's about making a change to your web site that the CA can confirm. Obviously they need DNS to reach the site so that's affected.

3.2.2.4.7 puts the change into DNS directly. A better option for Let's Encrypt in most cases, and the only one of these methods that's cryptographically secure end to end (if you deploy DNSSEC).

3.2.2.4.8 turns things upside down and validates based on you having previously proved you control an IP address, then they do a DNS lookup to find that the DNS name you're asking for has an A or AAAA record with that address. This might, maybe, be a good way to get the cert for 1.1.1.1 or things like that, but I will not be astonished if this goes away.

3.2.2.4.9 instead of changing a web page you put a dummy certificate up, created by the CA (not a real cert, it's just to prove you can change the certificate).

3.2.2.4.10 is how the tls-sni-01 (now abandoned) and tls-alpn-01 (new hotness) features in Let's Encrypt work. You do TLS setup, but then you (ab)use that to prove your identity instead of actually delivering a good cert, since if you already had a good cert you wouldn't be trying to get one.

3.2.2.4.12 says basically if you're the DNS registrar AND a Certificate Authority then you can issue everybody who has names under your domain with certificates, since you know who they are.

As you can see, most of these methods depend on DNS, a few don't but are relying on something that makes DNS look like Fort Knox. 3.2.2.4.12 only sidesteps this by making your DNS registrar also your CA, so if they broke into your DNS registrar account they would still get a cert.

Post reply on HN