Shqyrtime për DNSSEC
DNSSEC nga Antoine POPINEAU
40 shqyrtime
- Vlerësuar me 2 yje nga 5 të mundshëmnga Ærion, 2 muaj më parëThis used to work fine, but now reports 100% of websites as "not secure by DNSSEC" when using Cloudflare as the resolver. Setting it to Google solves the problem.
Ultimately though this extension needs support for custom DoH resolvers. - Vlerësuar me 2 yje nga 5 të mundshëmnga Korwin, një vit më parëWhile cloudflare.com/ssl/encrypted-sni/#results tells me that "DNSSEC. Attackers cannot trick you into visiting a fake website by manipulating DNS responses for domains that are outside their control," this extension claims that "cloudflare.com not secure by DNSSEC. Domain www.cloudflare.com is not secure through DNSSEC. Your connection is prone to man-in-the-middle attacks."
- Vlerësuar me 4 yje nga 5 të mundshëmnga Wolfizen, një vit më parëResults inaccurate when choosing Cloudflare as the resolver, but can be worked around by choosing Google as the resolver. No option for custom resolver or even native recursive resolution.
- Vlerësuar me 3 yje nga 5 të mundshëmnga 18361289 përdoruesi Firefox-i, një vit më parëCan hopefully be made even better with https://bugzilla.mozilla.org/show_bug.cgi?id=1852752
- Vlerësuar me 1 yje nga 5 të mundshëmnga PSYCHOPATHiO, një vit më parëthis is only a choice of 1.1.1.1 or 8.8.8.8 that i can manually enter in settings, poitless i guess
- Vlerësuar me 2 yje nga 5 të mundshëmnga Popi, 2 vite më parëUnfortunately we never got to choose the resolver, and now it just stopped providing accurate results altogether.
- Vlerësuar me 2 yje nga 5 të mundshëmnga JB, 3 vite më parëThis use to work... but now no longer works.
- Vlerësuar me 5 yje nga 5 të mundshëmnga 7035052 përdoruesi Firefox-i, 3 vite më parëWow! A DNSSEC extension that works! And no extra steps to install either.
- Vlerësuar me 2 yje nga 5 të mundshëmnga CognitiveFeline, 4 vite më parëused to display info and change but now it just always stays at NOPE doubt it's nope and 99% sure it's not me causing it.
- Vlerësuar me 1 yje nga 5 të mundshëmnga ploedman, 4 vite më parëRecently the Addon shows my Domain as "not secure by DNSSEC". But 3 Website to test the DNSSEC status says the Domain is secured by DNSSEC.
- Vlerësuar me 2 yje nga 5 të mundshëmnga MarSanMar, 4 vite më parëActualmente, esta extensión no funciona. La usé mucho tiempo y estaba contento con su funcionamiento, pero ahora mismo he tenido que buscar una alternativa.
- Vlerësuar me 5 yje nga 5 të mundshëmnga Jernej, 4 vite më parë
- Vlerësuar me 1 yje nga 5 të mundshëmnga 13662450 përdoruesi Firefox-i, 5 vite më parëNo longer works. Was good in the past, but these days say 100% of websites are not secured by DNSSEC, which is outright wrong.
- Vlerësuar me 4 yje nga 5 të mundshëmnga Trashify, 5 vite më parë
- Vlerësuar me 5 yje nga 5 të mundshëmnga Asclepius, 5 vite më parëThank you for this add-on. I just hope (since it isn't a "recommended" extension) that it is trustworthy. Aside from that concern, it serves its purpose. It would be nice if Firefox had built-in DNSSEC validation.
- Vlerësuar me 5 yje nga 5 të mundshëmnga Boris Volkov, 5 vite më parë
- Vlerësuar me 4 yje nga 5 të mundshëmnga 15136226 përdoruesi Firefox-i, 6 vite më parëThis add on works well, however there are some issues as pointed out by other reviewers. I would like to note that ECDSAP256SHA256 works for me. It would also be nice if the add on verified https sites with DANE pinned certificates.
- Vlerësuar me 4 yje nga 5 të mundshëmnga 14672905 përdoruesi Firefox-i, 6 vite më parëIt's great! And yes, would be even better once we have custom DNS, over TLS or not.
But this is a feature I have been waiting for so long, so I'm not going to hide my current feeling about this extension, it's awesome!! - Vlerësuar me 1 yje nga 5 të mundshëmnga _ztv, 6 vite më parëWell there, the future has not come yet?
- Vlerësuar me 3 yje nga 5 të mundshëmnga 13680056 përdoruesi Firefox-i, 6 vite më parëIt will be nice to choose a custom DNSSec, I don't trust on google, and some ISP redirect the 1.1.1.1 to his own DNS.
- Vlerësuar me 5 yje nga 5 të mundshëmnga 15299958 përdoruesi Firefox-i, 6 vite më parë
- Vlerësuar me 1 yje nga 5 të mundshëmnga Renaud, 6 vite më parëUsing Cloudflare and Google for validation is not a good idea.
But also, validation fails for some kind of signatures, exemple: those using ECDSAP256SHA256. - Vlerësuar me 5 yje nga 5 të mundshëmnga 14754691 përdoruesi Firefox-i, 6 vite më parë
- Vlerësuar me 2 yje nga 5 të mundshëmnga 14514156 përdoruesi Firefox-i, 7 vite më parëI would give at least 4 stars, if it would use my local resolver instead of using google/cloudflare for DNS lookups.
Reason behind the downgrade:
1. it introduces a single point of failure:
if either of those sites can't answer, _ALL_ users of this extension (who have configured that site) can't use it, if it would use the local resolver and that failed it would be just the users of the local machine who experience that problem.
2. it is a privacy hazard:
a hacker needs to crack only a single (ok: two) machine(s) to get a complete log of who on this world tried to communicate with which web server....
if it would use the local configured resolver that _might_ still be a problem, depending on the configuration of said resolver, but mostly (I hope) those will contact multiple authoritative servers to walk from the root to the leaf containing the desired information and only the _last_ server will know which site I wanted to contact, but there it's irrelevant, since _that_ site knows it anyway.... (btw.: _THIS_ is the reason why I disabled this extension)
3. it can't verify local domains
according to 'dig' my own domains are DNSSEC enabled and working correctly, still your extension reports them as unsigned because there is no global glue record, as such while it is reachable from the world (via dyndns), the world doesn't see the DNSSEC information stored on my local dns-server. - Vlerësuar me 2 yje nga 5 të mundshëmnga IPv777, 7 vite më parëPlease let the user choose (a text input) his own DNS resolver(s)