that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).
No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.
Really hard to understand why that hasn't happened yet!
You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.
But sure, keep spreading FUD like you always do on this topic.
For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.
You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).
Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.
if the only evidence of a crime is on your phone, what kind of crime is it?
we should always be asking: is this the only way you can prove the accusation? just because it would make LEO life easier - that's not justification for violating the constitution.
an consider what this case teaches us: clean up your devices before you cross a border. how does that even help the goal of law enforcement?
at most, you should configure your system and OS to give them a chance. for instance, being 100% full all the time is just bad. use TRIM and log SMART metrics.
why do you think this is a function of betas? or even of OS or app versions?
I guess you've been burned, or are worried about being burned, by some software that generated excessive writes? I think you need to describe that first, since this is a rare phenomenon.
which is probably why there isn't some kind of downdetector infra tracking it.
you know you can access smart counters on any OS, right?
reply