Bitcoin Forum
May 02, 2024, 08:20:12 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Why no DNSSEC requirements for seed nodes? (and why none on bitcoin.org)  (Read 121 times)
DaveF (OP)
Legendary
*
Offline Offline

Activity: 3472
Merit: 6259


Crypto Swap Exchange


View Profile WWW
June 05, 2021, 02:04:36 PM
Merited by ABCbits (1)
 #1

Was going to open an issue in github but figured I would post here in case it had been discussed before and I am having a Google / DuckDuckGo fail in search terms.
Was looking in chainparams.cpp for something and wondered how many seeds used dnssec, checked and the answer was 3 out of 9
Did a little more looking and bitcoin.org and bitcointalk.org don't use it either.

Yes I *know* it's a minor thing. But it does help in security.
I can see not having it here, but elsewhere come on. It's not that tough.

If you are going to run a seed node then I feel that should be requirement.
Any thoughts?

*full disclosure I don't have it on 99% of my own stuff so I am not one to really criticize but, I am not responsible for other peoples money either so there is that....

Either way, it's finally a nice weekend. If you need me I'll be outside....

-Dave


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
1714681212
Hero Member
*
Offline Offline

Posts: 1714681212

View Profile Personal Message (Offline)

Ignore
1714681212
Reply with quote  #2

1714681212
Report to moderator
1714681212
Hero Member
*
Offline Offline

Posts: 1714681212

View Profile Personal Message (Offline)

Ignore
1714681212
Reply with quote  #2

1714681212
Report to moderator
1714681212
Hero Member
*
Offline Offline

Posts: 1714681212

View Profile Personal Message (Offline)

Ignore
1714681212
Reply with quote  #2

1714681212
Report to moderator
The grue lurks in the darkest places of the earth. Its favorite diet is adventurers, but its insatiable appetite is tempered by its fear of light. No grue has ever been seen by the light of day, and few have survived its fearsome jaws to tell the tale.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714681212
Hero Member
*
Offline Offline

Posts: 1714681212

View Profile Personal Message (Offline)

Ignore
1714681212
Reply with quote  #2

1714681212
Report to moderator
NotATether
Legendary
*
Offline Offline

Activity: 1596
Merit: 6723


bitcoincleanup.com / bitmixlist.org


View Profile WWW
June 05, 2021, 02:25:53 PM
 #2

Because of complexity perhaps? Managing HTTPS certificates, and getting them to work in the first place, is hard enough. I can't imagine how much more difficult manually creating and adding certificates to their nodes or other arbitrary software would be, unless bitcoin-seeder gets the functionality to do those things automatically merged, which is unlikely.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
DaveF (OP)
Legendary
*
Offline Offline

Activity: 3472
Merit: 6259


Crypto Swap Exchange


View Profile WWW
June 05, 2021, 02:40:48 PM
 #3

Because of complexity perhaps? Managing HTTPS certificates, and getting them to work in the first place, is hard enough. I can't imagine how much more difficult manually creating and adding certificates to their nodes or other arbitrary software would be, unless bitcoin-seeder gets the functionality to do those things automatically merged, which is unlikely.

It's not the nodes it's the DNS for the nodes.
https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions

Just about every major DNS provider supports it.
If you want to host a seed node it just seems like a good piece of extra security to be sure that when someone looks up your address it really is you on the other side.


-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
ABCbits
Legendary
*
Offline Offline

Activity: 2870
Merit: 7452


Crypto Swap Exchange


View Profile
June 06, 2021, 09:14:07 AM
Merited by vapourminer (1)
 #4

Was going to open an issue in github but figured I would post here in case it had been discussed before and I am having a Google / DuckDuckGo fail in search terms.

Here are some discussion about or mention DNSSEC,

ops: Enable DNSSEC on all Bitcoin DNS Seed domain names
p2p: monoculture of DNS seeder software
Is EFF's proposed Sovereign Key system similar to how Namecoin/Bitcoin works?

Looks like some people think DNSSEC doesn't have big impact and prefer seed diversity.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
DaveF (OP)
Legendary
*
Offline Offline

Activity: 3472
Merit: 6259


Crypto Swap Exchange


View Profile WWW
June 07, 2021, 12:19:52 AM
 #5

Looks like some people think DNSSEC doesn't have big impact and prefer seed diversity.

 Huh So instead of being sure that the node your are connecting to is the actual node not one that was forged by a DNS attack nobody outside of 3 people want to put in the effort.

:sigh: sometimes some really smart people can make silly decisions.

Will leave this thread open for a bit see if anyone else chimes in.

-Dave

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!