Live data from Hacker News

Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

news.ycombinator.com

121–123 of 123 posts

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#121
post #94
post #91

Earlier quoted context omitted.

> From a site reliability perspective HTTPS is still broken. Some 15yo OS can't access any site because it doesn't have the certificates or cipher suites Sorry, but this argument doesn't hold water And this coming from someone who supports systems still running NT 4 I have fallback rules enabled on all of my domains - TLS 1.3 is preferred, but older editions will be supported if the need arises (1.2, 1.1, and 1.0 (on…

Doesn't that enable downgrade attacks?

When you need to support older OSes, does it matter?

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#122

Earlier quoted context omitted.

But if a bunch of large, well-staffed, engineering-focused, otherwise competent organizations manage to fuck it up regularly, the problem's probably above the individual organizations. Potentially with the spec itself.

I've seen far more failed certificate renewal failures than DNSSEC failures from the same teams you appear to be suggesting are perfect and the standard is flawed.

The consequences of a failed certificate renewal are much smaller than the consequences of a DNSSEC failure: if you screw up DNSSEC, your site falls off the Internet, as if it never existed.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#123

Earlier quoted context omitted.

I've seen far more failed certificate renewal failures than DNSSEC failures from the same teams you appear to be suggesting are perfect and the standard is flawed.

The consequences of a failed certificate renewal are much smaller than the consequences of a DNSSEC failure: if you screw up DNSSEC, your site falls off the Internet, as if it never existed.

Now you are changing the topic. I take this to mean I am correct.
Post reply on HN