Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

21–30 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#22
post #6

[deleted]

If you don't know for sure that that is a post by a cloudflare employee then I suggest you change the text or delete the comment.

When google rolls out a new feature there are 10's of submissions around the theme and surely not all of those are by google employees, why should cloudflare be any different?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#24
I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is:

https://news.ycombinator.com/item?id=10539418

If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#25
post #24

I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.

That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#27
It's great to see this microsite (and the announcement yesterday) as this rollout by CloudFlare will do two major things to help move DNSSEC forward:

1. Simplify the process of setting up DNSSEC-signing for so many people; and

2. Advance the usage of stronger crypto through the used of ECDSA (DNSSEC algorithm 13).

The first point will help with getting many more domains signed. The second point will help those of us who want to see even stronger crypto used within DNSSEC.

On that last note, I'd also note that there is an Internet Draft submitted about adding Ed25519 as a new DNSSEC crypto algorithm. You can find it here:

https://tools.ietf.org/html/draft-sury-dnskey-ed25519-01

Support for this draft within the IETF working groups - and indeed in implementations - will help make this a reality.

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#30
post #24

I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.

That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.

"DNSSEC: everything will be fine as long as everyone moves to domains in Bouvet Island's .BV. Brought to you by Cloudflare."
Post reply on HN