Something something DANE cook: Microsoft pledges to wrap its email systems in secure anti-snooping protocol
(2020/04/07)
- Reference: 1586297836
- News link: https://www.theregister.co.uk/2020/04/07/microsoft_dane_office/
- Source link:
Microsoft will add DNSSEC and DNS-based Authentication of Named Entities (DANE) to its email systems by the end of the year, the software giant has announced. That'll be a big thumbs up for the pair of internet security technologies.
“Today we are announcing that Exchange Online will be adding support for two new Internet standards specific to SMTP traffic. These standards are DNSSEC (Domain Name System Security Extensions) and DANE for SMTP (DNS-based Authentication of Named Entities),” announced a Redmond [1]blog post .
The [2]DANE [3]protocol has been around for years. The German government mandated its use [4]in 2016 , for instance. However, take-up has been slow in much the same way that the related [5]DNSSEC protocol has taken a long time to take hold, and with how the IPv6 protocol is still lagging.
Implementing the protocol requires a significant investment of time and effort, not least because misconfigurations can cause it to fail. Microsoft noted that adding DANE “will require investment and architecture changes to the Microsoft infrastructure.” It has decided it is worth it though, largely because existing protocols aren’t sufficiently secure. The ubiquitous SMTP email protocol “was designed a long time ago, when message delivery was considered more important than security,” its post notes.
Salesforce takes the multi-signer DNSSEC ball and runs with it [6]READ MORE
SMTP is not secure, and while SMTP over TLS offers additional security through encryption, it is still potentially vulnerable: a miscreant on the network path can insert a server between you and the SMTP server you wish to reach, with this in-between machine masquerading as the legit service. This man-in-the-middle attack effectively strips out the encryption, and allows the content of messages to be snooped on as they flow from you, through the middle box, to the desired destination.
DANE, however, allows email systems to authenticate other SMTP gateways before sending any message data, by using TLSA DNS resource records. These records can be used to [7]verify a TLS encryption certificate presented by a server is legit. If someone tries to man-in-the-middle your connection by impersonating an SMTP server, its malicious certificate won't match the specifications in the server's domain name's DNS records, which specify what a legit cert should look like, and thus the connection can be aborted.
Here's Microsoft’s explanation: “DANE uses the presence of DNS TLSA resource records to securely signal TLS support to ensure sending servers can successfully authenticate legitimate receiving email servers. This makes the secure connection resistant to downgrade and MITM attacks.”
Basically it’s secure email and Microsoft will be adding it to Office 365 Exchange Online.
Two phases
Highlighting the difficulty of rolling out DANE across a large system however, the Windows giant will be rolling it out in two phases. The first phase, to be completed by the end of 2020, will cover outbound email, and then the IT titan is giving itself another year, the end of 2021, to cover inbound email.
The announcement was met with something bordering close to joy by DANE advocates. “Welcome to the DANE SMTP community, congratulations and thanks!,” commented Viktor Dukhovni, one of the originators of the protocol who started work on it back in 2013 and has been pushing for its adoption for years.
“If this comes to pass, we'll all owe Viktor a beer,” [8]commented internet veteran Paul Vixie. “I can't easily describe what this could mean for the future of internet security. Real lived security, not the theatrical kind. Viktor had been almost like a one man band on this.”
Although there are quite a few email providers that offer DANE – Comcast perhaps being the largest – the addition of Microsoft to the list could prove to be a tipping point for the industry. But, as ever, with DNS protocols, it is a slow-moving process because there’s little point in adopting a new protocol until everyone else has – a chicken-and-egg situation.
DANE rides on top of DNSSEC and requires domains to be DNSSEC-signed to work. Fortunately more and more domains do include DNSSEC, but the problem then becomes in deciding what to do with emails to and from domains that aren’t signed. And then there are the endless misconfigurations that exist everywhere on the network.
With a giant like Microsoft saying it will adopt DANE, it provides an impetus to others to also take the jump and sign their domains as well as check their configurations. ®
Sponsored: [9]How to Build Your Digital Experience Portfolio
[1] https://techcommunity.microsoft.com/t5/exchange-team-blog/support-of-dane-and-dnssec-in-office-365-exchange-online/ba-p/1275494
[2] https://datatracker.ietf.org/doc/rfc6698/
[3] https://datatracker.ietf.org/doc/rfc7671/
[4] https://www.theregister.co.uk/2016/05/23/germany_says_yes_to_dane/
[5] https://www.internetsociety.org/resources/deploy360/2011/dnssec-rfcs-3/
[6] https://www.theregister.co.uk/2019/08/15/salesforce_multi_signer_dnssec/
[7] https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities#TLSA_RR
[8] https://twitter.com/paulvixie/status/1247437265426452482
[9] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936
“Today we are announcing that Exchange Online will be adding support for two new Internet standards specific to SMTP traffic. These standards are DNSSEC (Domain Name System Security Extensions) and DANE for SMTP (DNS-based Authentication of Named Entities),” announced a Redmond [1]blog post .
The [2]DANE [3]protocol has been around for years. The German government mandated its use [4]in 2016 , for instance. However, take-up has been slow in much the same way that the related [5]DNSSEC protocol has taken a long time to take hold, and with how the IPv6 protocol is still lagging.
Implementing the protocol requires a significant investment of time and effort, not least because misconfigurations can cause it to fail. Microsoft noted that adding DANE “will require investment and architecture changes to the Microsoft infrastructure.” It has decided it is worth it though, largely because existing protocols aren’t sufficiently secure. The ubiquitous SMTP email protocol “was designed a long time ago, when message delivery was considered more important than security,” its post notes.
Salesforce takes the multi-signer DNSSEC ball and runs with it [6]READ MORE
SMTP is not secure, and while SMTP over TLS offers additional security through encryption, it is still potentially vulnerable: a miscreant on the network path can insert a server between you and the SMTP server you wish to reach, with this in-between machine masquerading as the legit service. This man-in-the-middle attack effectively strips out the encryption, and allows the content of messages to be snooped on as they flow from you, through the middle box, to the desired destination.
DANE, however, allows email systems to authenticate other SMTP gateways before sending any message data, by using TLSA DNS resource records. These records can be used to [7]verify a TLS encryption certificate presented by a server is legit. If someone tries to man-in-the-middle your connection by impersonating an SMTP server, its malicious certificate won't match the specifications in the server's domain name's DNS records, which specify what a legit cert should look like, and thus the connection can be aborted.
Here's Microsoft’s explanation: “DANE uses the presence of DNS TLSA resource records to securely signal TLS support to ensure sending servers can successfully authenticate legitimate receiving email servers. This makes the secure connection resistant to downgrade and MITM attacks.”
Basically it’s secure email and Microsoft will be adding it to Office 365 Exchange Online.
Two phases
Highlighting the difficulty of rolling out DANE across a large system however, the Windows giant will be rolling it out in two phases. The first phase, to be completed by the end of 2020, will cover outbound email, and then the IT titan is giving itself another year, the end of 2021, to cover inbound email.
The announcement was met with something bordering close to joy by DANE advocates. “Welcome to the DANE SMTP community, congratulations and thanks!,” commented Viktor Dukhovni, one of the originators of the protocol who started work on it back in 2013 and has been pushing for its adoption for years.
“If this comes to pass, we'll all owe Viktor a beer,” [8]commented internet veteran Paul Vixie. “I can't easily describe what this could mean for the future of internet security. Real lived security, not the theatrical kind. Viktor had been almost like a one man band on this.”
Although there are quite a few email providers that offer DANE – Comcast perhaps being the largest – the addition of Microsoft to the list could prove to be a tipping point for the industry. But, as ever, with DNS protocols, it is a slow-moving process because there’s little point in adopting a new protocol until everyone else has – a chicken-and-egg situation.
DANE rides on top of DNSSEC and requires domains to be DNSSEC-signed to work. Fortunately more and more domains do include DNSSEC, but the problem then becomes in deciding what to do with emails to and from domains that aren’t signed. And then there are the endless misconfigurations that exist everywhere on the network.
With a giant like Microsoft saying it will adopt DANE, it provides an impetus to others to also take the jump and sign their domains as well as check their configurations. ®
Sponsored: [9]How to Build Your Digital Experience Portfolio
[1] https://techcommunity.microsoft.com/t5/exchange-team-blog/support-of-dane-and-dnssec-in-office-365-exchange-online/ba-p/1275494
[2] https://datatracker.ietf.org/doc/rfc6698/
[3] https://datatracker.ietf.org/doc/rfc7671/
[4] https://www.theregister.co.uk/2016/05/23/germany_says_yes_to_dane/
[5] https://www.internetsociety.org/resources/deploy360/2011/dnssec-rfcs-3/
[6] https://www.theregister.co.uk/2019/08/15/salesforce_multi_signer_dnssec/
[7] https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities#TLSA_RR
[8] https://twitter.com/paulvixie/status/1247437265426452482
[9] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936
Let me see if I understand this...
You do away with the whole PKI infrastructure and you check that a DNNSEC signed cert is verified by by the top level DNS servers and use this certificate to setup a TLS connection over which your usual SMTP type hello traffic goes over?
So nothing really changes in so far as MS GOOGLE and other NSA data providers are concerned because you don't encrypt the content but only encrypt the channel still. It's a bit a of as shame that eMail cannot use the certificates to encrypt the content so that only the domain owner can read it, but rather still encrypts only to the MX.
If you just wanted to verify the MX, which is all that you are doing, you could just check that the certificate it presents you is signed for the right host name, and you could still use the PKI.
I was never happy with the revocation thing in certs, but if you use short TTLs you can achieve that same without adding that complexity.