[openpgp] Re: Certificate discovery over HKP
Bart Butler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <xkUv7_eibLgJYnt2q9RghjHQfOiDbC_eX2zSMGLOLSLdm2pt9qAdU8YEd27Mrphz6vmlFgatTbtjKYey3INxk8HE7oeiN0OWxVaiR8hixcc=@pm.me> |
Hi Andrew, > And I do appreciate that the same argument applies to DANE etc. over DNS-non-SEC. But it's a regression when compared to WKD over TLS. We could give clients the discretion to only consider DNSSEC-secured WKD paths if they want, or to indicate this differently in their key discovery UI. Or even require it--at this point, the vast majority of TLDs are DNSSEC-enabled and deploying it for domain owners is as easy as using CloudFlare as their DNS provider and hitting a switch. The world is in a very different position for DNSSEC deployment today than it was even 3 or 4 years ago. https://stats.dnssec-tools.org/#/?top=dane&trend_tab=0 If we did require DNSSEC (and client verification of it) this makes the client's work slightly harder, and life harder for certain TLDs/deployers. On the other hand, my bet is that it makes it much easier for many, many other domains to deploy domain-based key discovery. I'd take that tradeoff: there are many fewer client implementers than domains that would benefit from this, so that shift in complexity is a good thing. -Bart On Wednesday, April 9th, 2025 at 11:56 AM, Andrew Gallagher <[email protected]> wrote: > On 9 Apr 2025, at 10:40, Daniel Huigens <[email protected]> wrote: > > > > > So the only difference here is that the attack is silent also for the > > sender, in the sense that they will still see that the message will be > > encrypted, if they trust the keyserver. Perhaps that's still significant > > in the sense that they might be more willing to send sensitive data in > > an encrypted email (but then again, you could argue that in that case > > they should verify the key first). > > > Agreed, but we’ve spent enough time telling people to look for lock icons that a significant number of them will behave differently when the lock icon appears - in which case we’re giving them a false sense of security. Sure, they *should* verify out of band, but how many will in practice? > > And I do appreciate that the same argument applies to DANE etc. over DNS-non-SEC. But it's a regression when compared to WKD over TLS. > > A > _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0Fgmf2W38JkJkFRGXvMx5ERRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmfC82kZoCfQZQtXGxbBBd7cAaFiJQl45l3YqIb0 OVSuHxYhBDwVkTeBh+6myif6rJkFRGXvMx5EAAB47AEAqtw38VC/zZkNIzOi m1Wv0SA6dNVgLSL6cGEu/zquemEBAKWbCbR8kRPUpYGo7HO//k+aIPh19U8a 0Z/oFpYWpWQP =kK+R -----END PGP SIGNATURE-----