5 ms·
Almost nobody has DNSSEC enabled. Against DNSSEC: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
by empthought 3mo ago
Almost nobody has DNSSEC enabled.
Against DNSSEC: https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- gerdesj 3mo agoThat article kicks off with a politically motivated "issue" which seems pointed at the US Govt (USG) before dealing with perceived architectural issues. The thing about trust anchors is that they are trust anchors and not a back door. DNSSEC goes well out of its way too, to not screw up things as far as possible if something is missing. OK, client implementations do that (I haven't gone into the RFCs in too much detail). The architectural issues alluded to seem pretty handwavy too. I deployed a slack handful of PowerDNS boxes and adding DNSSEC is basically two CLI invocations per domain and passing on the DS records to upstream. The second invocation is to add an adjustment to deal with NXDOMAIN better (can't remember the exact thing at the moment) If it doesn't work for you then fine - don't use it! I find it useful and thanks to a decent implementation (so far) it is trivial to implement. However, I'm going to need to get my thinking cap on for some split-horizon domains.
- tptacek 3mo agoIt doesn't work for most sites, which is why so few organizations use it. It's awfully hard to make an argument about how straightforward DNSSEC is to use after DNSSEC had to be disabled by Cloudflare and Quad9 for all of Germany because of a misconfiguration. And it's more or less impossible to take seriously as a security boundary after that. Real security protocols fail closed.
- gerdesj 3mo agoA fuck up or two doesn't invalidate DNSSEC. IT related security is hard, really hard as you well know, but not impossible nor likely perfect and always a moving target. Putting security on top of DNS is really, really hard because DNS was invented rather a long time ago when information wanted to be free and not fettered and I wore short trousers at school and in the distant future would run an IBM System /36! When you confidently insist on "most sites" you appear to want to rudely trample on my experience of "it works for me and my 20 at the moment DNS domains and increasing as I migrate them over". I'm taking my time - I have quite a few more to do and each one needs adding to monitoring etc. I don't run .de and I do feel for the lads n lasses that do that buggered up a KSK roll over or whatever it was that was screwed. I think that holding up a screw up is an extremely crass and facile argument against ... anything, let alone a rather esoteric engineering function. I don't agree with your assertion about "Real security protocols fail closed." That sounds like striving for perfection and you know as well as I do that perfect is the enemy of good. DNSSEC for better or worse is what we have and I don't think it is too bad. It does give some guarantees within certain parameters. Any decent engineer will look at the risks/rewards and decide on effectiveness and design their solutions to a requirement ... accordingly.
- tptacek 3mo agoI came to this thread with data. Your 20-at-the-moment DNS domains versus the current signing statistics of the Tranco Top 1000. At the point where we're arguing about fail-open versus fail-closed, our premises are too far apart to get anywhere. We can part company here: I'm speaking, in part, for the people who believe that any viable security protocol must fail closed. Plenty of security protocols have ultimately failed in the marketplace and been abandoned. DNSSEC is simply another one of them.
- gerdesj 3mo agoYou have deployed proof by assertion - I am powerless. I am only describing my own experience and not pontificating on behalf of the world.
- inigyou 3mo agotptacek is HN's resident DNSSEC hater. I think he also hates IPv6.
- tptacek 3mo agoI built the IPv6 private network system at Fly.io.
- gerdesj 3mo agoLet's keep the discussion civil please
- inigyou 3mo agoThat is civil. It's relevant and important to know that tptacek is present in every thread about DNSSEC and he always posts many comments opposing it, usually with little actual substance beyond "most people don't use it therefore it must suck"
- 3mo ago
- messh 3mo agoI have it enabled for an ssh interface for managing linux vms: https://shellbox.dev https://shellbox.dev Even supports post quantum encryption :)
- moquilabs 3mo agoIn the FAQ of this article it says: > What’s the alternative to DNSSEC? > Do nothing. The DNS does not urgently need to be secured. > All effective security on the Internet assumes that DNS lookups are unsafe. This is not true, our entire infrastructure of ACME certificate authorities like let's encrypt are fundamentally dependent on DNS: https://letsencrypt.org/how-it-works/#domain-validation https://letsencrypt.org/how-it-works/#domain-validation Then TLS verifies the domain with the private key the certificate authority issues... How can you trust the s (secure) in https then?? Can anyone provide an example of "effective security on the Internet"?
- tptacek 3mo agoVirtually none of the most important sites on the Internet are signed. When's the last time one was maliciously misissued?
- moquilabs 3mo agoFair point. I'm just looking for a way to cryptographically prove that my website is from me in a way that browsers will accept. This means the whole chain from ICANN -> Verisign -> registrar -> dns -> IP -> my server.
- tptacek 3mo ago1. Browsers briefly tried adopting DANE and gave up on it. 2. DNS is the wrong level of networking abstraction to do this kind of policy enforcement at, because DNS isn't plumbed for warnings and error reporting; when DNSSEC fails, whole zones simply fall of the Internet (for people who validate) as if they weren't there at all. It's the worst possible failure mode. 3. The thing you say you want can't be had with DNSSEC. You don't get "the whole chain from ICANN to your server". Any of the parent zone operators above you can decide to defect, for your zone specifically, and (particularly for state-level adversaries) for particular targets resolving your zones, without you ever knowing about it.
- 3mo ago