Earlier quoted context omitted.
Is darronz a CloudFlare employee?
Let me ask jgrahamc, I'll get back to you ;)
Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
21–30 of 112 posts
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#22[deleted]
When google rolls out a new feature there are 10's of submissions around the theme and surely not all of those are by google employees, why should cloudflare be any different?
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#23[deleted]
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#24https://news.ycombinator.com/item?id=10539418
If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#25I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#26Does this seem ironic to anyone else considering CloudFlares SSL offering essentially is a MITM attack?
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#271. Simplify the process of setting up DNSSEC-signing for so many people; and
2. Advance the usage of stronger crypto through the used of ECDSA (DNSSEC algorithm 13).
The first point will help with getting many more domains signed. The second point will help those of us who want to see even stronger crypto used within DNSSEC.
On that last note, I'd also note that there is an Internet Draft submitted about adding Ed25519 as a new DNSSEC crypto algorithm. You can find it here:
https://tools.ietf.org/html/draft-sury-dnskey-ed25519-01
Support for this draft within the IETF working groups - and indeed in implementations - will help make this a reality.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#28Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#29DNSCurve and DNSCrypt are the better solutions for slightly different problems that I think we should be pushing.
Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain
#30I think it's important that those of you who haven't read up on DNSSEC understand how bad an idea it is: https://news.ycombinator.com/item?id=10539418 If DNSSEC had been deployed a few years back, Muammar Gadaffi could conceivably controlled BIT.LY's TLS keys. Yesterday, today, and tomorrow, DNSSEC gives the NSA immense control over the TLS keys of sites in .COM, .ORG, .NET, .CO.UK, .IO, .COM.AU, and many more.
That's what it means to have a domain in Libya - you're subject to the jurisdiction of the officially recognized Libyan government. If you don't want to have to deal with the whims of a crazy dictator, don't register your business in his country.