Private key of DigiCert Certificate Transparency log compromised
feistyduck.com
feistyduck.com
(the attacker doesn't seem to realize that they gained access to the keys and were running other services on the instracture)
Agreed. CC mining would be CPU on most servers, and go undetected for the same reasons. Some servers and gaming rigs would have GPUs, but not many vs CPUs.
They were of course mining on GPUs.
If you do not assume that everything bad that could have happened, did happen, then you will have some interesting explaining to do later, with lawyers.
https://ssl.engineering.nyu.edu/blog/2020-02-03-transparent-...
CT is a narrow solution to a narrow problem. We had that specific problem, and so this is a very good solution. You almost certainly don't have that problem, our solution can't help you, we aren't sorry about that.
(Conversely, multiple CT server compromises would be a significant concern, but even then without a compromised Certificate Authority, the impact is almost zero.)
It’s time for DANE [1]. We don’t need any more “men in the middle.”
[1] https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na...
Also, DANE relies on DNSSEC [1], which is bad.
I think this would be true except my statement wasn't just about SCT but the CA system in general. Furthermore, browsers like Firefox [1] do not even have CT checks.
> Also, DANE relies on DNSSEC [1], which is bad.
Handshake completes this system [2].
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1281469
[1a] https://developer.mozilla.org/en-US/docs/Web/Security/Certif...
Auditors and monitors are the real protection you get from CT logs.
You get the same problem with any form of DNS validation because you'll never get every little caching server to validate records.
If that works, I call ARPcoin next.
DNSSEC is a Government-Controlled PKI -> Not if the root of trust is secured by a proof-of-work blockchain
DNSSEC is Cryptographically Weak -> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605
DNSSEC is Unsafe -> NSEC3 is mentioned by the article itself
DNSSEC is Expensive To Deploy -> We can make tools for this, so much has gotten easier already
DNSSEC is Incomplete -> Agreed, we need browser adoption
https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoc...
https://paragonie.com/blog/2017/07/chronicle-will-make-you-q...
> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605
First: That's a big "if". Lots of RSA legacy support.
Furthermore, ECDSA is so bad that Ed25519 and Ed448 are even coming to FIPS 186-5 later this year.
Citing ECDSA adoption in DNSSEC doesn't make as strong of a case as you might think.
"Currently [2018], in more than 90% of cases if a user passes DNS queries to a resolver that performs DNSSEC validation of an RSA digital signature the same resolver will also perform DNSSEC validation of ECDSA P-256 digital signatures."
https://blog.apnic.net/2018/08/23/measuring-ecdsa-in-dnssec-...
"Since the second quarter of 2019 [to the first quarter of 2020], the population of [strict DNSSEC] validating users has risen from 12% to 22%, close to doubling. At the same time, the proportion of [non-strict DNSSEC validating] users has risen from 5% to 10%."
https://blog.apnic.net/2020/03/02/dnssec-validation-revisite...
The web PKI, by contrast, requires users to trust a bunch of CAs, any one of which could have been compromised by a government and can issue a certificate for your domain. Also, if a government can compromise your DNS records, they can also be granted domain-validated certificates for those domains, so the web PKI is not an improvement.
Anyway, if your threat model is that every single country in the world is willing to subvert the security of their own DNS hierarchy specifically to attack you, then the limitations of DNSSEC are the least of your worries.
[0] https://twitter.com/ln4711/status/754516056878772224
[1] https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-deleg...
In contrast, when it becomes clear that the United States Government controls multiple certificate authorities, that won't be a problem for any websites.