HSTS for new TLDs
imperialviolet.org
imperialviolet.org
It will allow for pinning certificates (self-signed too) to records in in DNS with DNSSEC.
No, DNSSEC has nothing to do with CAs. Each DNS authority defines its own keys used to sign its records.
> They were just renamed to "Trust Anchors".
You are thinking about DANE [1], which is what the a protocol on top of DNSSEC. Using DANE you authorize X.509 certificates and/or CAs for certain domains. This allows you to restrict your domain to a specific well-known CA (such as Verisign), but it also allows you to authorize your own CA or even a specific certificate directly. It even works per-service, so you do not need to use the same CA/certificates for all your services.
If you were suggesting that DANE does not solve the traditional CA issue you are wrong.
[1] http://tools.ietf.org/html/rfc6698
> The trust anchor for .com is Verisign.
Err.. no? I don't even understand what are you trying to say here. The "com" domain does not seem to have any TLSA records...
>Err.. no? I don't even understand what are you trying to say here. The "com" domain does not seem to have any TLSA records...
Verisign runs the "com." zone, so I guess they would have to admin any DNSSEC/DANE/TLSA stuff.
The DANE part needs no further support than you being able to use DNSSEC for your domain's DNS. Obviously there is always some entity controling each TLD, and that entity can screw up your domain if it acts improperly.
You're interpreting "CA" too literally. DNSSEC doesn't rely on X509 certificate authorities but in effect it relies on an equivalent, in that Verisign is a central authority certifying ownership of all .com domains.
And shouldn't it be possible to implement certificate pinning for whole tlds? Then we'd only have to trust root for unknown tlds.
Second, and more importantly: the smaller number of trust anchors you end up with in DNSSEC are controlled by world governments.
It seems absurd to me that the Internet's response to the "global passive adversary" of NSA would be to hand the entire PKI system over to the USG formally. That's what DNSSEC does.
They already are, in practice. Many reputable CAs will issue certificates to anyone who can forge an MX record for a domain. With or without DNSSEC, TLD operators are capable of forging those records.
>It seems absurd to me that the Internet's response to the "global passive adversary" of NSA would be to hand the entire PKI system over to the USG formally. That's what DNSSEC does.
No, DNSSEC builds authentication into a system that is and has always been centrally controlled. And just like with the X.509 CA system, you can use pinning or Convergence or anything else you want to supplement that.
which in turn must be signed by the zone operator (e.g.: Verisign for .com) who publishes them in DNS. So we still have Central Authorities - in the sense that there is still some overlord controlling everything.
[2] https://www.youtube.com/watch?v=pDmj_xe7EIQ (you can skip the first 5 minutes; if you want to jump straight to his proposed solution, it's around 35 minutes in)
[3] http://www.theregister.co.uk/2011/09/08/google_chrome_reject...
If people just accept any cert they see anyone could just mitm them with a self signed cert.
I don't know if Namecoin itself will be the solution, or some other blockchain-based method that achieves decentralization such as the more generic Ethereum [2], but as engineers we should be supportive of such systems, as they provide better security and true -not just delegated- domain name ownership.
Actually, the problem is exactly the opposite. Any CA can sign a certificate for any domain.
What compounds the problem with the CA system is that CA trust is sticky. When a new CA gets added to trust stores, they are effectively trusted for life. That's not how trust actually works.
What we need is a system that is distributed and that allows for trust to be granted and - most importantly - revoked at will without causing collateral damage (i.e. for innocent sites that end up using a bad CA).
Moxie Marlinspike's convergence[0] was a great idea, but it's never really taken off. TACK[1], also by Marlinspike, looks like nice feature to help transition away from the CA system when we come up with something better.
HSTS is only a header.
did you read evilpie's link?
"Only if a host responds with a valid HSTS header with an appropriately large max-age value (currently greater than or equal to 10886400, which is eighteen weeks) do we include it in our list. ... We limit the list to hosts that send a large max-age under the assumption that these sites will not revert to non-HSTS status."
Maybe one of these Firefoxes should say Chrome