Earlier quoted context omitted.
> From a site reliability perspective HTTPS is still broken. Some 15yo OS can't access any site because it doesn't have the certificates or cipher suites Sorry, but this argument doesn't hold water And this coming from someone who supports systems still running NT 4 I have fallback rules enabled on all of my domains - TLS 1.3 is preferred, but older editions will be supported if the need arises (1.2, 1.1, and 1.0 (on…
Doesn't that enable downgrade attacks?
Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days
121–123 of 123 posts
Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days
#122Earlier quoted context omitted.
But if a bunch of large, well-staffed, engineering-focused, otherwise competent organizations manage to fuck it up regularly, the problem's probably above the individual organizations. Potentially with the spec itself.
I've seen far more failed certificate renewal failures than DNSSEC failures from the same teams you appear to be suggesting are perfect and the standard is flawed.
Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days
#123Earlier quoted context omitted.
I've seen far more failed certificate renewal failures than DNSSEC failures from the same teams you appear to be suggesting are perfect and the standard is flawed.
The consequences of a failed certificate renewal are much smaller than the consequences of a DNSSEC failure: if you screw up DNSSEC, your site falls off the Internet, as if it never existed.