Conversation

I'm considering writing a zine about owning a domain! (DNS! registrars! certificates! TLS! HSTS! MX records!). What questions do you have about domains? Will try to answer as many as I can.
234
2,319
Replying to
someone might yell at me for saying this but I've never had to learn anything about DNSSEC and I'm not convinced it's in any way useful to learn for most people
3
12
Replying to and
is that true? I've heard a lot of people say that DNSSEC is going to be important in the future, but I've never seen an explanation I understood for why. It seems like everyone who's really into DNSSEC thinks the CA model for TLS is broken? is that right?
1
1
Replying to and
There have been previous, and likely will be plenty more, vulns discovered in DNS leading to cache poisoning, etc.; false DNS records. These fake records trick users into visiting fake sites, downloading malware, or worse. DNSSEC solves that problem.
1
Replying to and
Email servers also don't inherently validate based on CAs. Authenticated encryption for email is provided through setting a key or certificate in DNS via a DANE TLSA record. MTS-STS is a weak alternative still depending on DNS security and works like HSTS does without preloading.
1
2
Replying to and
CAs aren't actually required to validate DNSSEC and certificates are issued based on showing control of the domain via unauthenticated DNS, HTTP or SMTP. Most CAs hopefully do validate DNSSEC and respect the requirement to validate the CAA record, which helps to mitigate this.
1
2
Show replies