23 ms·
Who owns your domain name? Hint: it’s probably not you. Your hosting provider could take down your domain, or even steal traffic and direct it to their own IPs
by rbren 3mo ago
Who owns your domain name? Hint: it’s probably not you. Your hosting provider could take down your domain, or even steal traffic and direct it to their own IPs
- PunchyHamster 3mo agoBut without private keys they can't pretend to be the same you. There is a very big difference here.
- chuckadams 3mo agoRight, if Bluesky ever does do something hinky with your PDS, the operation will be signed with their key and persisted in the operation log which they're unable to touch. You can outright remove Bluesky's key if you want, though I think that only works within some number of days of creating it.
- PunchyHamster 3mo agoIt's probably one of few places where blockchain would be actually useful; just use it as a history of users keys to validate against, so any domain takeover or similar event would at least not allow stealing user's handle
- opem 3mo agothat is why you have did:plc in ATProto but that doesn't resolve the concerns raised in this article.
- handoflixue 3mo agoCan you move a DNS record AND make it look like I signed off on it? The author's concern seems to be more focused on impersonation
- Zambyte 3mo agoDo you use your own CA? Would you expect users to even notice if the certs were suddenly issued by LetsEncrypt? Or are you signing traffic using something other than TLS, where the domain name doesn't really matter anyway?
- EGreg 3mo agoYes you do own your domain, as much as you can own your house. Your hosting provider can only take down your hosting, not your domain. Seizing domain names isn't very common. And by the way, with Web3 domains, you have full ownership via your own private key, with no need to pay rent. Is it possible to lose your house that you own? Yes. It's far more rare to lose a domain you own, by it being seized. DNSSec is used to prevent unauthorized stealing of domains. Furthermore, if someone does steal one domain you own, they don't steal all your accounts across all domains. If they take over your hosting, that's a fixable problem -- you just repoint the domain. Now, having said that, I designed the Safebox exactly to prevent these scenarios from happening, and create an actually solid foundation for decentralized social networking, AI workloads, etc. If anyone is interested, probably the best link to begin reading about it is: https://safebots.ai/about https://safebots.ai/about (If you do, I'd love to hear your thoughts)
- tptacek 3mo agoIn addition to the fact that almost nobody uses DNSSEC, it solves none of the problems indicated by this article.
- EGreg 3mo agoRight, but neither do these problems apply to domains, as much as they apply to ATProto accounts. You don't even have the frameworks that are available to protect domains. (Domain lock, transfer, etc.) And registrars are regulated by laws and frameworks in ways ATProto hosts aren't. Don't get me wrong, if a registrar transfers your domain due to a social engineering attack on the registrar, then you might lose it (an attacker almost did this to me once via a SIM swap, and I had to call GoDaddy to prevent the transfers). But that's not the same as, say, hacking the web hosting server. In any case, tptacek, Safebox is supposed to solve these actual problems, by making sure no one can actually get into the box (no ssh, etc) so it's a "neutral ground" that no one can really "own", "redirect", steal keys or impersonate you. If you read https://safebots.ai/about https://safebots.ai/about you'll see what I'm talking about. If you do, I'd love to read any feedback you might have, given your background in security!
- 3mo ago
- Aurornis 3mo agoThis cheap criticism of the headline doesn’t actually apply to the problems brought up in the article: > Your PDS operator can post as you, like things as you, follow people as you, and it would be cryptographically indistinguishable from your real activity. The signatures are valid. Your domain name owner or DNS provider cannot redirect your domain name to a different server and cryptographically impersonate you.
- jacobgold 3mo agoYour DNS provider can obtain a TLS certificate for your domain and cryptographically impersonate https://yourdomain.tld https://yourdomain.tld It's not exactly the same thing but it's close.
- Aurornis 3mo agoStill not the same thing as in the article. Server side TLS certificates are widely understood to be tied to the current owner of the domain. In a social protocol or context, I would expect a private key to be in the private control of the individual, such as when someone uses their private key to sign an email or git commit. The purpose of signing your emails or commits is to provide a good indicator that it actually came from you, not someone who managed to get access to your email account at the time.
- jacobgold 3mo agoThis is why your DNS hosting provider, despite not being the "current owner of the domain", being able to impersonate your site (terminate a cryptographically secure TLS session) with your customers is a similar problem. I do agree they're not the same but the trust and risk are very similar.
- edoceo 3mo agoDNS providers and registrars seem to have a longer trust established, that reduces the risk. They are similar in that: jerks can be jerks. But one of the jerks I've trusted for 30 years and I hardly know the the other jerk.
- nekusar 3mo agoIf its an Onion (Tor) hostname, you absolutely do own it. Sure, its not memorable being a 128 bit hash. And nobody else can impersonate nor take. And for lower bandwidth tasks, Tor Onions can't be beat. Just make sure to use 2fa on services you offer to keep the trash out. Things like fail2ban don't work the way you intend.
- pocksuppet 3mo agoLet me just require a phone number for my totally anonymous drug-market service
- drdexebtjl 3mo agoI do. I registered it directly with my ccTLD’s registry, which is a government agency. It’s tied to my national ID number, or to my company’s tax ID. If my DNS provider messes up, I revoke their DNSSEC keys and point my domain to a different provider. Domain registration should be national public infrastructure.
- pocksuppet 3mo agoMore importantly, ICANN can seize your domain if you don't comply with US law (e.g. if you call for a boycott of Israel) unless it's under another country's ccTLD.