BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- Date: Sun, 07 Dec 2014 14:57:45 -0500
- In-reply-to: <5484A441.3040301@horne.net>
- References: <sjm8uirdxem.fsf@securerf.ihtfp.org> <BN3PR0401MB1204B299B351DFF7F2E85FBDDC7D0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjmlhmqcb1j.fsf@securerf.ihtfp.org> <BN3PR0401MB120492A5BDE4D3CEE0AECDD3DC7A0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uiqc7sw.fsf@securerf.ihtfp.org> <547E0FB3.3070005@gmail.com> <sjmy4qobui6.fsf@securerf.ihtfp.org> <547F3855.10106@gmail.com> <sjmtx1bbf7w.fsf@securerf.ihtfp.org> <5480856D.6050205@gmail.com> <20141204163645.GA11641@dragontoe.org> <54809327.5040802@gmail.com> <225b01d00fe5$dde00d40$99a027c0$@Polcari.com> <5480A14C.1080303@gmail.com> <CA+h9Qs5wWchqNJxCWQ4ty7RaFSd+JtfFS6hVQQF19-0O2ZnqDQ@mail.gmail.com> <5481D65F.7050104@gmail.com> <5484A441.3040301@horne.net>
On 12/7/2014 2:02 PM, Bill Horne wrote: > Of course, theory and practice often differ in security, and we've all > met mister "JustDoItOrYou'reFired" who likes to tell us to break the > rules, but that isn't a technical problem. A well designed security > suite will give Joe the option of sending his reports by encrypting them > first with a few key clicks. Therein lies what I consider to be the most egregious flaw in DNSSEC from an end user's perspective: no choice. Joe has no choice but to use it and accept that he can't work at all when it comes under attack assuming DNSSEC is being enforced which is contrary to DNSSEC mandatory requirements but that's a tangent. I'm not saying that DNSSEC is flawed (well, I think it is, but that's another tangent). I'm saying that DNSSEC is not an end user's tool and that you're going to experience serious problems if you try to use it as one. In my opinion, a well-designed -- that is, well-designed for end users -- secure DNS system should provide reliable, authenticated answers despite attacks made against the system. DNSSEC does not do this. It doesn't try because, like I wrote way back at the start of all this, it's a last hop issue that lies outside of the scope of DNSSEC. A few days ago Ed posited that we'll get there someday. Truth is, we've been there for some time. With DNSCurve and DNSCrypt we have exactly the kinds of encrypted DNS service that he called for. Why haven't they been widely adopted? I figure it's a "Paul Vixie, yes! DJB, no!" issue. -- Rich P.
- Follow-Ups:
- [Discuss] free SSL certs from the EFF
- From: bill at horne.net (Bill Horne)
- [Discuss] free SSL certs from the EFF
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: Joe at Polcari.com (Joe Polcari)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: jabr at blu.org (John Abreau)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: bill at horne.net (Bill Horne)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] free SSL certs from the EFF
- Next by Date: [Discuss] DNSSEC
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):