Live data from Hacker News

Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

news.ycombinator.com

61–70 of 123 posts

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#61
post #44

Earlier quoted context omitted.

My apologies if you read it as a snide remark. I'm usually baffled when support is demanded on free stuff, but i see your point in this particular scenario.

No one "read it as a snide remark"- you were snide and rude. Just own it and apologize.

I did and i removed the parent comment. If you'd like me to delete everything, i'd be happy to oblige.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#62
post #55

Earlier quoted context omitted.

Disabling DNSSEC doesn't propagate instantly. Have you queried the CF nameservers for the domain directly? In my experience everything involving DNSSEC requires a 24h wait (unless the domain hasn't been queried from anywhere - but that's usually not the case, something might have triggered distributed DNS lookups e.g. LE doing DNS validation for cert issuance etc).

CF's authorative servers ("hasslo" and "crystal") respond correctly when queried directly, but that doesn't really help the situation.

Then it sounds like you are caught in cache limbo. It might be prudent for CF to have their DNSSEC setup so that users can't disable it instantly (or enable again instantly) and have a minimum of 12/24/48h between changing DNSSEC state. I'd guess that by now most caching DNS resolvers might have different signatures (old registrar, first CF DNSSEC and second CF DNSSC).

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#63

Reading this hurts. I see that @elithrar has given out his email address and is following up but I will also be following this internally to understand what happened.

Since the issue was made public, we'd love to see some details in case OP (throwaway) doesn't come back.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#64
post #45
post #12

Earlier quoted context omitted.

It like https. A lot of people in the past viewed HTTPS as a terrible idea that just broke things, and every example where someone had their website go down because of broken certificates or mixed content was proof that https as a concept was broken. Usually people brought up x.509 or revocation lists as the definitive proof that https would never be common.

Eh, except that HTTPS actually has tangible benefits, unlike DNSSEC.

Without DNSSEC anyone can intercept your email. The TLS cert verified by mail is the domain pointed to by the MX record. Plus with DKIM keys store in DNS people can spoof email (if they can fool the receiver to trust their records). If you can fool DNS resolution for LetsEncrypt (pretty hard since IIRC they fetch DNS from multiple perspectives on the internet to mitigate this) you can get certificates for any hostname.

There are other solutions such as MTA-STS and DNS-over-HTTP but the end-to-end validation of DNSSEC is pretty powerful.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#65
Enterprise plans no longer come with "premium" support either, you are looking at 20% over contract value to get a similar level of previously included support and an SLA. To be fair, CloudFlare provides a lot of services for free and $20 premium plan with upgraded support seems like a pretty good deal!

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#66
post #50

Earlier quoted context omitted.

I've had several sites with HTTPS work for many years now with zero effort or SRE time. Let's Encrypt via certbot handles it all for me

Lucky you. I’ve had multiple problems like rate limits, cron not firing, let’s encrypt servers not being able to see challenge files because of obscure rewrite rules… it’s far from flawless

I don't think of it as luck, more about good devops practices and not letting tech debt creep

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#68
post #54

DNSSEC is notorious for breaking things [1]. I use it on most of my domains, but I would not just 'enable' it on a domain that I cared about and that had real users without a lot of thought and planning. Nor should you. [1] - https://ianix.com/pub/dnssec-outages.html

> DNSSEC is notorious for breaking things

My understanding is that people break things.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#69
post #65

Enterprise plans no longer come with "premium" support either, you are looking at 20% over contract value to get a similar level of previously included support and an SLA. To be fair, CloudFlare provides a lot of services for free and $20 premium plan with upgraded support seems like a pretty good deal!

For any form of business endeavour that would be the obvious lowest starting point. For private users a $20/mo. price tag for registering one or a few domains would turn effective TLD pricing on its head. Suddenly owning a single .net domain is no longer $20 per year like it is with all the other thousand registrars, but instead it would be $260 per year.

Cloudflare's kind policy of zero markup on domain registrations on a free plan is remarkably generous. OK, sure, the traffic data has an obvious value to them, but maybe the support environment could improve with, I dunno, a tiny 5% markup.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#70

Reading this hurts. I see that @elithrar has given out his email address and is following up but I will also be following this internally to understand what happened.

Since the issue was made public, we'd love to see some details in case OP (throwaway) doesn't come back.

I'll be back.
Post reply on HN