HNHacker News
TopNewBestAskShowJobs

sadpluto

9 karma · joined June 22, 2012

I'm beginning a new blog (my very first!) which will probably be a long series of quasi Ask HN posts, although they will be edited with curated results and feedback. Please bear with me while I submit my own posts at first... Hopefully this won't be needed for long!

blog.sadpluto.com

submissionscomments
sadpluto··on Ask HN: Hetzner's Terms and Conditions: "full name and address must be present"
I think a little search answers my own question. From [Google's cache of][1] I see that it refers to commercial activities.

  § 6 Identification of providers

  Concerning commercial offers, providers shall indicate:

    1. their name and address as well as, 
    2. in case of associations and groups of persons, the
       name and address of their authorized representative.
It makes much more sense now, though of course it raises the typical question as to what is a commercial offer. For instance, would a blog with Google ads qualify? But I digress... Never mind!

[1] http://www.iuscomp.org/gla/statutes/TDG.htm

sadpluto··on Show HN: A date range picker for Twitter Bootstrap
Are there Bootstrap tutorials that also combine the minimal CSS knowledge required in order to use it? For instance, I have a vague understanding of the box model, and can hand-code very simple pages myself, but I find it unsatisfactory, as the nested divs and knowing what class to use when can drive me a bit nuts. So far the tutorials I've come across don't add much to the official documentation at all.

I'm hoping this lean book [1] will give me a nice, integrated walk through these issues.

[1] http://www.amazon.com/Twitter-Bootstrap/dp/6201519254/

sadpluto··on The DNS-Based Authentication of Named Entities Transport Layer Security Protocol
Does your decentralized ideal apply to the whole Internet, or just TLD signing and such? In other words, do you believe we'd be better off without a DNS root zone? I know there's Freenet, so I guess another question is whether you think that shift could ever become mainstream.

If so, I'd love a reply.

If not, I'd love a reply. And! And then... this DANE shift would not be such a bad thing, right? You have the hierarchy anyway, so why not have the option of securely publishing [1] your public keys. By the time you have registered your domain and paid all your fees, you might as well!

As for the potentially insecure signing of some TLDs, isn't it partly due to the decentralized nature of the ccTLDs? From a security perspective people may have to learn to trust more .com domains with a green lock than, say, .ly.

[1] I'm purposely using this loaded term, as I'm full of doubt and confusion, hoping to provoke the master and get more thoughts! Refer, for instance, to my TL comment in this thread.

sadpluto··on The DNS-Based Authentication of Named Entities Transport Layer Security Protocol
How can DANE ever work if DNS (including DNSSEC) is an unencrypted protocol? Doesn't this mean that the moment you get a response to a DNS query the a malicious network could return orchestrated nonsense?

It looks like something like DNSCurve [1] would be needed, though Paul Vixie stated [2]:

  [...] the problems DNSCurve actually does solve are pretty well solved by UDP source port randomization and will be entirely eradicated by DNSSEC [...]
How does it solve the encryption problem?

[1] http://dnscurve.org/

[2] http://www.isc.org/community/blog/201002/whither-dnscurve

sadpluto··on Living with HTTPS
Wow. Thank you very much for educating us, Thomas. Your comments require grabbing some popcorn or equivalent. In particular when you engage in a constructive debate with someone of your caliber. One of my all-time favorite threads in HN (or elsewhere...) is http://news.ycombinator.com/item?id=893659. Thanks again.
sadpluto··on Living with HTTPS
Thanks for answering! What I don't understand is that, given that your starting point is "two computers talking over a malicious network", doesn't the current state of affairs of (unencrypted)DNS mean that it's game over from the outset? That is, if the network is malicious, that MITM could very refer you to an invalid IP address the moment you first try to resolve, say, mail.google.com.

Please don't take this as an argument. I just want to know where I'm wrong! I just can't get over the idea of pushing at the (justifiably) paranoid level for HTTPS while we still have plain-text DNS... even with DNSSEC!

Wish request: Your thoughts on http://news.ycombinator.com/item?id=4268461.

sadpluto··on Paul Vixie: Whither DNSCurve? [2010]
Could security experts give their take on this? There are some strong statements, such as the last sentence: "Because DNSCurve does not do this, and because the problems DNSCurve actually does solve are pretty well solved by UDP source port randomization and will be entirely eradicated by DNSSEC, ISC is not investing in DNSCurve at all."

I have a few questions, in case anybody is interested in any of them:

1) Would full deployment of IPsec render DNSCurve unnecessary?

2) Isn't "full security" impossible until DNS queries are encrypted? I'm reading the ongoing comments about HSTS [+] and can't help to think that, if you assume the network is a malicious medium, then any unencrypted DNS query, including DNSSEC, can receive a compromised response. But then again, Paul Vixie's quoted sentence seems to counter my reasoning/understanding.

[+] http://news.ycombinator.com/item?id=4266626

sadpluto··on Living with HTTPS
Thanks for your answer! I'm more confused by the moment about DNSSEC et al: isn't the DNSSEC-based validation of HTTPS referred to above supposed to get rid of CAs in the future? That wouldn't make sense even with DNSSEC considering that the information is not encrypted? (Right?) I hope you don't take this as "hijacking", but I'd be most curious about what you and other security experts think about Paul Vixie's "Whither DNSCurve?" [1], which has amazingly not been submitted in HN. I just submitted it [2].

(If I could vote for your time investment, please kindly consider commenting on that article before replying to this comment.)

Thanks again!

[1] http://www.isc.org/community/blog/201002/whither-dnscurve

[2] http://news.ycombinator.com/item?id=4268461

sadpluto··on Living with HTTPS
In [1] you showed us how to authenticate via DNSSEC HTTPS in Chrome. If I understand correctly this involves a lookup of a TYPE257 record. Given that only 5% can resolve TXT records, do you know what % of Chrome users can then resolve TYPE257 records?

Digressing a bit further, wouldn't you say that even if HSTS is enabled and registered in the all the browsers' built-in list, you still have the problem of unencrypted DNS lookups? (Maybe this kind of attack is orders of magnitude harder to implement. I honestly don't know.)

[1] http://www.imperialviolet.org/2011/06/16/dnssecchrome.html

sadpluto··on A few facts and a few questions on DNSSEC
Hello everyone! I know... I'm still submitting my own articles. On my defense I'll just say it's article #2... I hereby promise I will not do it once I reach #10. I feel it may be of interest to some, in particular the collection of links, and on the other hand my current readership... gives me no choice if I want to share it with the outside world!
sadpluto··on So You Want to Be a Security Expert
What is the standard reference for DOM mastery?