Hacker Newsnew | past | comments | ask | show | jobs | submit | markhahn's commentslogin

that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).

I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...


No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.

Really hard to understand why that hasn't happened yet!


You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.


For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.

https://dnssecmenot.fly.dev/

The PKI run by state-level actors isn't going to happen.


> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?


You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).

Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.

if the only evidence of a crime is on your phone, what kind of crime is it?

we should always be asking: is this the only way you can prove the accusation? just because it would make LEO life easier - that's not justification for violating the constitution.

an consider what this case teaches us: clean up your devices before you cross a border. how does that even help the goal of law enforcement?


devices already do wear management.

at most, you should configure your system and OS to give them a chance. for instance, being 100% full all the time is just bad. use TRIM and log SMART metrics.


why do you think this is a function of betas? or even of OS or app versions?

I guess you've been burned, or are worried about being burned, by some software that generated excessive writes? I think you need to describe that first, since this is a rare phenomenon.

which is probably why there isn't some kind of downdetector infra tracking it.

you know you can access smart counters on any OS, right?


uh-huh. and what source code do you think coding models are trained on?


smells of AI-pilled management viewpoint. the kind who think that AI has already changed the whole software landscape.


I'm curious what you mean by "violence" here.


Generally you can infer they mean taxation.


Or what happens to them if they try to "opt out" of paying those taxes.


it wouldn't be a triangle if it meant embracing one of the poles.


first, eliminate record-keepers.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: