Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why are the organizations who can sign TLDs, or the DNS administrators who manages names under those TLDs, somehow more trustworthy than CAs? Some of the most desirable TLDs today are assigned to random governments by pure accident of fate and orthography. That problem is only getting worse now that the TLD namespace has been put up to the highest bidder.

The monolothic CA model has largely failed, and this draft merely seeks to reorganize it. Apart from "not needing to do business with CAs", that's the only value provided by DANE: your DNS administrators are now your CAs.

This isn't a win; it's a push.

In the short term, the untrustworthy CA problem can be addressed tactically through pinning, which provides key continuity. TACK is a protocol proposed by Trevor Perrin and Moxie Marlinspike to do that using only the insecure DNS we have now.

Over the long term, we need to engage with the fact that this is a UX problem, not a protocol problem. We haven't figured out how to encode the policy decisions we are requiring users to make into browser UIs. Moxie Marlinspike's Convergence system, which is a step towards a web-of-trust style peer-to-peer verification system (it would allow, say, the EFF to create a trust anchor for its followers), is one example of a genuine rethinking of the Internet trust model.

Taking the trust model we have now and baking it into a core Internet protocol seems like exactly the wrong thing to do. Centralized PKI isn't working. The right response isn't "double down on PKI".



Does your decentralized ideal apply to the whole Internet, or just TLD signing and such? In other words, do you believe we'd be better off without a DNS root zone? I know there's Freenet, so I guess another question is whether you think that shift could ever become mainstream.

If so, I'd love a reply.

If not, I'd love a reply. And! And then... this DANE shift would not be such a bad thing, right? You have the hierarchy anyway, so why not have the option of securely publishing [1] your public keys. By the time you have registered your domain and paid all your fees, you might as well!

As for the potentially insecure signing of some TLDs, isn't it partly due to the decentralized nature of the ccTLDs? From a security perspective people may have to learn to trust more .com domains with a green lock than, say, .ly.

[1] I'm purposely using this loaded term, as I'm full of doubt and confusion, hoping to provoke the master and get more thoughts! Refer, for instance, to my TL comment in this thread.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: