DNSSEC isn't an imperfect protocol; it's harmful, a net loss.
And here we have Snowden twice advocating for it.
DNSSEC isn't an imperfect protocol; it's harmful, a net loss.
And here we have Snowden twice advocating for it.
And as Chrome experimented with DANE then removed support for it, I don't think you have to worry about that either.
But even if you did - so what? There are CAs in areas controlled by the American and British and French and Chinese governments already. I don't see how it makes anything different.
2. DNSSEC is harmful for reasons that go past DANE.
3. I am worried about DNSSEC; I think it's a more reasonable thing to be worried about w/r/t/ surveillance than 95% of what's been posted to The Intercept.
4. QUANTUM INSERT will work fine in an all-DNSSEC world.
5. You can revoke a CA. It has happened more than once. You can't revoke a TLD.
I'm happy to talk more about how I think DANE CAs are different and worse than the 20391 X509 CAs we have today, but I'm not sure you're asking me to go on at length about that.
Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mistaken.
I'm still not sure how you arrive at the conclusion that it is a net loss. Which attacks will DNSSEC enable that are not possible today? If you mean that it will give people a false sense of security, is that not the same as TLS today? Despite my hangups with the CA system I think we're better off with TLS than without it.
The NSA certainly has no problems with intercepting DNS requests today with their QUANTUM tools.
I am genuinely interested in hearing other ideas about how to provide confidentiality and authentication for DNS without central trust. Since you have clearly investigated these matters, I would like to ask again, are you aware of any promising projects or ideas in this regard? Because I would jump into the anti-DNSSEC camp in a heartbeat if one existed.
You make a strong argument that DNSSEC cannot deliver any real advantages. I did not see anything to support your earlier statement that it's worse than nothing, but given the general uselessness of the protocol, I certainly won't be deploying it.