Post #2349491
2026-05-10 16:53 UTC
@casar@mastodon.social @whitequark@social.treehouse.systems after babysitting DANE at my mail server, I’d say it’s a good thing that it’s not going to happen.
DNS is not realtime and keys rotation is a nightmare of non-predictable duration. The best you can do is to not rotate keys, so fingerprints do not change.
DANE requires to establish trust in DNS first and DNSSEC can compete with IPv6 on deployment rate. Heck, even some TLDs still don’t have DNSSEC roots.
As we seen this week a tiny little mistake in RR during key rotation is what it takes to bring whole TLD down. Now imagine this but with DANE on top of it. CF-scale outage in a brewing.
It’s a miracle that we finally have CA that can issue certs for bare IP addresses, which can’t happen with DANE by design.
There are tons of things that CA based TLS do that DANE just can’t by design. Especially it allows you to make and fix mistakes. Which will always happen.
While CA-based PKI is an actively burning dumpster fire, it’s still better in practice than anything DANE can offer in theory
We need some other way to establish trust between parties without central authority, but it’s one of the “millennia problems” of infosec, which is not solved yet
Replies (0)
No replies.