Critiques pour DNSSEC
DNSSEC par Antoine POPINEAU
33 notes
- Noté 2 sur 5par CognitiveFeline, il y a 8 moisused to display info and change but now it just always stays at NOPE doubt it's nope and 99% sure it's not me causing it.
- Noté 1 sur 5par ploedman, il y a 8 moisRecently the Addon shows my Domain as "not secure by DNSSEC". But 3 Website to test the DNSSEC status says the Domain is secured by DNSSEC.
- Noté 2 sur 5par MarSanMar, il y a 8 moisActualmente, esta extensión no funciona. La usé mucho tiempo y estaba contento con su funcionamiento, pero ahora mismo he tenido que buscar una alternativa.
- Noté 5 sur 5par Jernej, il y a 9 mois
- Noté 5 sur 5par Utilisateur ou utilisatrice 13662450 de Firefox, il y a 2 ans
- Noté 2 sur 5par mario, il y a 2 ans
- Noté 4 sur 5par Trashify, il y a 2 ans
- Noté 5 sur 5par Asclepius, il y a 2 ansThank you for this add-on. I just hope (since it isn't a "recommended" extension) that it is trustworthy. Aside from that concern, it serves its purpose. It would be nice if Firefox had built-in DNSSEC validation.
- Noté 5 sur 5par Boris Volkov, il y a 2 ans
- Noté 4 sur 5par Utilisateur ou utilisatrice 15136226 de Firefox, il y a 3 ansThis add on works well, however there are some issues as pointed out by other reviewers. I would like to note that ECDSAP256SHA256 works for me. It would also be nice if the add on verified https sites with DANE pinned certificates.
- Noté 4 sur 5par Utilisateur ou utilisatrice 14672905 de Firefox, il y a 3 ansIt's great! And yes, would be even better once we have custom DNS, over TLS or not.
But this is a feature I have been waiting for so long, so I'm not going to hide my current feeling about this extension, it's awesome!! - Noté 3 sur 5par Utilisateur ou utilisatrice 13680056 de Firefox, il y a 3 ansIt will be nice to choose a custom DNSSec, I don't trust on google, and some ISP redirect the 1.1.1.1 to his own DNS.
- Noté 5 sur 5par Utilisateur ou utilisatrice 15299958 de Firefox, il y a 3 ans
- Noté 1 sur 5par Renaud, il y a 3 ansUsing Cloudflare and Google for validation is not a good idea.
But also, validation fails for some kind of signatures, exemple: those using ECDSAP256SHA256. - Noté 5 sur 5par Utilisateur ou utilisatrice 14754691 de Firefox, il y a 3 ans
- Noté 2 sur 5par Utilisateur ou utilisatrice 14514156 de Firefox, il y a 4 ansI would give at least 4 stars, if it would use my local resolver instead of using google/cloudflare for DNS lookups.
Reason behind the downgrade:
1. it introduces a single point of failure:
if either of those sites can't answer, _ALL_ users of this extension (who have configured that site) can't use it, if it would use the local resolver and that failed it would be just the users of the local machine who experience that problem.
2. it is a privacy hazard:
a hacker needs to crack only a single (ok: two) machine(s) to get a complete log of who on this world tried to communicate with which web server....
if it would use the local configured resolver that _might_ still be a problem, depending on the configuration of said resolver, but mostly (I hope) those will contact multiple authoritative servers to walk from the root to the leaf containing the desired information and only the _last_ server will know which site I wanted to contact, but there it's irrelevant, since _that_ site knows it anyway.... (btw.: _THIS_ is the reason why I disabled this extension)
3. it can't verify local domains
according to 'dig' my own domains are DNSSEC enabled and working correctly, still your extension reports them as unsigned because there is no global glue record, as such while it is reachable from the world (via dyndns), the world doesn't see the DNSSEC information stored on my local dns-server. - Noté 2 sur 5par IPv777, il y a 4 ansPlease let the user choose (a text input) his own DNS resolver(s)
- Noté 5 sur 5par Utilisateur ou utilisatrice 13310694 de Firefox, il y a 4 ans
- Noté 5 sur 5par YFdyh000, il y a 4 ans
- Noté 1 sur 5par Utilisateur ou utilisatrice 12553117 de Firefox, il y a 4 ansGood PoC, but -4 (would rate 0 if it was possible) for crap called CF and Google.
- Noté 4 sur 5par Utilisateur ou utilisatrice 14135084 de Firefox, il y a 4 ansI like the simple user interface style. Please add support for custom DNS server.
- Noté 5 sur 5par grahamperrin, il y a 4 ans
- Noté 4 sur 5par Utilisateur ou utilisatrice 12739246 de Firefox, il y a 4 ansGreat addon !
It just lacks the ability to set a custom DNS resolver, and the TLSA support.
Besides, the UI doesn't integrate well with a dark theme on Linux (KDE here, but I suspect it will be the same for another window manager), as the background of the tooltip gets its color from the system, and the font color seems to be hardcoded in black.
Oh, and I didn't find any link to the sourcecode. Is it available ? :)