[openpgp] Re: Certificate discovery over HKP

Bart Butler <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <xkUv7_eibLgJYnt2q9RghjHQfOiDbC_eX2zSMGLOLSLdm2pt9qAdU8YEd27Mrphz6vmlFgatTbtjKYey3INxk8HE7oeiN0OWxVaiR8hixcc=@pm.me>
Hi Andrew,


> And I do appreciate that the same argument applies to DANE etc. over DNS-non-SEC. But it's a regression when compared to WKD over TLS.

We could give clients the discretion to only consider DNSSEC-secured WKD paths if they want, or to indicate this differently in their key discovery UI. Or even require it--at this point, the vast majority of TLDs are DNSSEC-enabled and deploying it for domain owners is as easy as using CloudFlare as their DNS provider and hitting a switch. The world is in a very different position for DNSSEC deployment today than it was even 3 or 4 years ago.

https://stats.dnssec-tools.org/#/?top=dane&trend_tab=0

If we did require DNSSEC (and client verification of it) this makes the client's work slightly harder, and life harder for certain TLDs/deployers. On the other hand, my bet is that it makes it much easier for many, many other domains to deploy domain-based key discovery. I'd take that tradeoff: there are many fewer client implementers than domains that would benefit from this, so that shift in complexity is a good thing.

-Bart


On Wednesday, April 9th, 2025 at 11:56 AM, Andrew Gallagher <[email protected]> wrote:

> On 9 Apr 2025, at 10:40, Daniel Huigens <[email protected]> wrote:
> 

> > 

> > So the only difference here is that the attack is silent also for the
> > sender, in the sense that they will still see that the message will be
> > encrypted, if they trust the keyserver. Perhaps that's still significant
> > in the sense that they might be more willing to send sensitive data in
> > an encrypted email (but then again, you could argue that in that case
> > they should verify the key first).
> 

> 

> Agreed, but we’ve spent enough time telling people to look for lock icons that a significant number of them will behave differently when the lock icon appears - in which case we’re giving them a false sense of security. Sure, they *should* verify out of band, but how many will in practice?
> 

> And I do appreciate that the same argument applies to DANE etc. over DNS-non-SEC. But it's a regression when compared to WKD over TLS.
> 

> A
>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0Fgmf2W38JkJkFRGXvMx5ERRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmfC82kZoCfQZQtXGxbBBd7cAaFiJQl45l3YqIb0
OVSuHxYhBDwVkTeBh+6myif6rJkFRGXvMx5EAAB47AEAqtw38VC/zZkNIzOi
m1Wv0SA6dNVgLSL6cGEu/zquemEBAKWbCbR8kRPUpYGo7HO//k+aIPh19U8a
0Z/oFpYWpWQP
=kK+R
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.