Live data from Hacker News

Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

news.ycombinator.com

71–80 of 123 posts

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#71
post #67

> How can I get their attention without paying for an Enterprise plan? Just comment on HN and they'll crawl out of the woodwork.

Also, the community forums are generally quite useful when something isn't working. I've posted there with an actual problem maybe twice, but the problems were resolved within 30 minutes.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#72
post #42
post #6

Earlier quoted context omitted.

Can you please explain why DNSSEC was a bad idea in the first place? It worked perfectly fine with the old registrar.

Basically, it is lots of extra work effort for no real security advantages. Other people wrote a lot about it, here is an example: https://sockpuppet.org/blog/2015/01/15/against-dnssec/

Rebuttal: https://easydns.com/blog/2015/08/06/for-dnssec/

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#73
I'm also noticing that Cloudflare support is going terribly downhill.

I have an issue with the Cloudflare infrastructure on my domain since WEEKS, giving me thousands of 503 Service Temporarily Unavailable errors per day (cloudflare side, not the origin server) and nobody seems to care or able to resolve.

Removing the ability to create support tickets on free plan doesn't help at all, I mean, I get it why they're doing it, but asking on their community forum as an alternative it's not an acceptable solution. Neither going after Cloudflare employees on social media platforms hoping for a reply.

If I'm also going to pay for their services such as Zero Trust, domains registrar and R2, why do I have to switch to a Pro plan just to open a support ticket? Perhaps a middle-ground solution like 1 free support ticket per month on a free plan would be a good compromise?

I still think they're giving an incredible service and value for free, but this sucks.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#74
post #4

> what's the fastest way to get technical assistance when on a free plan? Upgrading to a non-free plan? You don't have to upgrade to enterprise, but even their $20/mo plan comes with support. (Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

Why was enabling DNSSEC a bad idea? Clearly the origin registrar isn't handling DNSSEC requests properly, but the OP should still be able to revert to non-DNSSEC without issues.

Wasn't there a thread on HN within the last couple of months that says switching back when things go wrong is actually very difficult? Intermediate servers or something cache the DNSSEC issues and things tend to break for 24 hours at a time. Unfortunately I can't remember the details.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#75
post #73

I'm also noticing that Cloudflare support is going terribly downhill. I have an issue with the Cloudflare infrastructure on my domain since WEEKS, giving me thousands of 503 Service Temporarily Unavailable errors per day (cloudflare side, not the origin server) and nobody seems to care or able to resolve. Removing the ability to create support tickets on free plan doesn't help at all, I mean, I get it why they're doi…

Can you email me (jgc@cloudflare.com) with details?

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#76
post #33
post #25

Earlier quoted context omitted.

Criminals are much less likely to engage in MITM attacks, besides TLAs it's usually shady ISPs who want to inject some content (similar to surveillance that could be made illegal too, ISPs would in fact care). And criminals also have little incentive to attack read-only sites. Even if they did it might be more efficient to allocate resources to law enforcement rather than securing everything that could theoretically…

They're not attacking the sites, they're attacking the users. Incentives are exactly the same with readonly sites. I'm a web programmer and I have no idea how the law enforcement could in any way help. Nor do I want them to. The idea that I have to cooperate with law enforcement to put a site online is absurd. See "Tech support scams" on YouTube to see what's being done today. We're talking about billion-dollar crime…

Another one for the list of attacking users....

You're updating the firmware on a server. The firmware is signed, so the attacker cannot outright put their own firmware on your system. The version you're using currently is secure, and the version you want to go to is secure, but there are versions in between that are insecure. All an attacker needs to do is modify the DNS and http stream to feed the firmware with an RCE to you, and then they can directly take over your server.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#77
post #29

Earlier quoted context omitted.

You should still protect against MITM attacks even with read-only websites - not all attacks are based on stealing user input.

What's the threat model here?

Ok, you have a site with signed firmware downloads. I mean, they are signed securely right? A user messing with the stream can only send you another signed firmware the device takes, and not anything they attempt to create (unless they guess your signing key somehow).

But, you make a mistake in firmware version XYZ and there is an RCE in it. So you pull it off your site and now XZZ is the latest version.

Only problem is, anyone that can MITM you can serve version XYZ that the client will accept and make the machine exploitable by an RCE.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#78
post #67

> How can I get their attention without paying for an Enterprise plan? Just comment on HN and they'll crawl out of the woodwork.

Also, the community forums are generally quite useful when something isn't working. I've posted there with an actual problem maybe twice, but the problems were resolved within 30 minutes.

Which is a bit strange. I would have guessed that the support ticket system would be prioritized by staff.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#79
post #4

> what's the fastest way to get technical assistance when on a free plan? Upgrading to a non-free plan? You don't have to upgrade to enterprise, but even their $20/mo plan comes with support. (Also, I hate to victim-blame here but using DNSSEC was a bad idea in the first place)

Why was enabling DNSSEC a bad idea? Clearly the origin registrar isn't handling DNSSEC requests properly, but the OP should still be able to revert to non-DNSSEC without issues.

>but the OP should still be able to revert to non-DNSSEC without issues.

Slack had a 24 hour outage doing exactly that; so I don't think "revert to non-DNSSEC without issues" is trivial at all.

Re: Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days

#80
post #4

Earlier quoted context omitted.

Why was enabling DNSSEC a bad idea? Clearly the origin registrar isn't handling DNSSEC requests properly, but the OP should still be able to revert to non-DNSSEC without issues.

This post makes a better argument than I could write. And nothing much has changed in the seven years since. https://sockpuppet.org/blog/2015/01/15/against-dnssec/

That article is a bad example of outdated arguments and whataboutisms. Sure, DNSSEC has some issues, but none are so bad that it means you shouldn't use it: It does help resolvers detect various attacks (e.g. cache poisoning, BGP hijacks, MitMs), which is fairly critical for security-minded organizations.

(from that article, that is from 2015 and woefully outdated)

> With TLS properly configured, DNSSEC adds nothing.

This is false. DNSSEC adds address lookup security through response integrity, whereas TLS (only!) adds transport layer security to the endpoint you're connected to (hence the name). If you find a record in DNS with DNSSEC enabled, you know that the response is exactly as the sender intended it to be (and when connecting to the address returned for A- or AAAA-records, you'll be connecting to the intended IP address). Without DNSSEC, this is impossible to guarantee and record interception / MitM would be an attack vector.

Additionally, "With TLS correctly configured" also implies CAA being set up, which only can be done securely using DNSSEC. As to why CAA must be configured: Not all CAs are made the same; and re-routing network traffic is fairly doable if you only need to target one of the many public CAs. Targeting only that CA allowed in the CAA record is presumably much harder.

> Securing DNS lookups isn’t a high-priority task

> DNSSEC’s real job is thus to replace the TLS CA system. This plan is called DANE.

No, DNSSEC's job _is_ to secure DNS lookups. DANE is only one scheme that is made possible by DNSSEC; Secure CAA checking being another.

> Real-world DNSSEC therefore relies on RSA with PKCS1v15 padding.

Correct, but also relies on Ed25519 and P-256. A lot of authorative servers are still using the legacy RSA keys, but another lot is using P-256 and Ed25519 too.

> [sections] DNSSEC is Expensive To Adopt / Deploy

This is partly true, but any security is expensive to adopt/deploy. DNSSEC is fairly easy nowadays, though, with many hosted DNS services providing some form of DNSSEC.

> DNSSEC doesn’t secure browser DNS lookups.

It would, if you allowed your browser to recurse.

> DNSSEC is Unsafe

> Authenticated denial. Offline signers. Secret hostnames. Pick two.

That's fine. Secrecy doesn't add security; Authenticated denial and Offline signers do.

> DNSSEC is Architecturally Unsound

I disagree with the conclusion here. Sure, it might be useful for US gov to be the writer of the spec, but what public scrutiny DNSSEC has had implies that the security part is sound.

Post reply on HN