Earlier quoted context omitted.
No, because nobody really depends on DNSSEC, so nothing will break: - https://ianix.com/pub/dnssec-outages.html - https://twitter.com/tqbf/status/772103926258671618
> because nobody really depends on DNSSEC That's not true. A lot of people use DNSSEC validating public resolvers like 1.1.1.1 and 8.8.8.8, especially on Android devices. I use DNSSEC on my personal domain, and when my zone-resigning cronjob fails, I notice pretty quickly, because the page really does fail to load in my browser.
First-ever DNSSEC root key rollover
31–40 of 75 posts
Re: First-ever DNSSEC root key rollover
#32But when will it be supported in Route53?
Re: First-ever DNSSEC root key rollover
#33Earlier quoted context omitted.
Cloudflare and Verisign are no surprise; Cloudflare has a DNSSEC product, and Verisign is effectively one of the sponsors of the protocol. For what it's worth: Akamai does DNSSEC, too. Comcast is indeed DNSSEC-signed (how you know Comcast does DNSSEC is, as I said, they sort of infamously broke an HBO product launch with it). But, for instance: Verizon and AT&T are not!
Also first national bank I tried to look up, (actually don't know if that's what you mean by national bank) federalreserve.gov is using dnssec.
Re: First-ever DNSSEC root key rollover
#34Earlier quoted context omitted.
> because nobody really depends on DNSSEC That's not true. A lot of people use DNSSEC validating public resolvers like 1.1.1.1 and 8.8.8.8, especially on Android devices. I use DNSSEC on my personal domain, and when my zone-resigning cronjob fails, I notice pretty quickly, because the page really does fail to load in my browser.
Is that a good thing? That sounds like a pretty solid reason not to deploy DNSSEC.
It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and drives lock-in for them, and that governments cheerlead because it in theory grants control over all web crypto to them.
Re: First-ever DNSSEC root key rollover
#35But when will it be supported in Route53?
But why do you want it? DNSSEC and TLS cover much of the same use cases - except DNSSEC is worse. IIRC, it uses 1024bit RSA keys - which are large, and yet not particularly strong. It gives you very little flexibility - if you own example.com, you have to trust the root key and Verisign and whatever governments have authority over them and the only way out is to change to a different domain name. And what seemed like…
Re: First-ever DNSSEC root key rollover
#36Earlier quoted context omitted.
DNSSEC precedes its first RFC by several years; before that RFC, it was a DoD-funded project run by Trusted Information Systems. It's different today in a variety of ways, but the fundamental design decisions --- offline signers, authenticated denial --- date back to TIS and the USG. If LetsEncrypt broke, there would be absolute chaos across the Internet.
Maybe, but LetsEncrypt breaking would be fixed much faster than any other CA as it’s the only one where every user is automated. Contrast that with the legacy model and the emailed zip files of cert chains alone would flood the intertubes.
Re: First-ever DNSSEC root key rollover
#37Earlier quoted context omitted.
Is that a good thing? That sounds like a pretty solid reason not to deploy DNSSEC.
It's not a good thing. To a first approximation 0% of the mainstream public Internet relies on DNSSEC, so using a DNSSEC-validating resolver will on net get you only new outages; not any additional security, even at the margin. It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and…
Re: First-ever DNSSEC root key rollover
#38Earlier quoted context omitted.
> if this actually has any effect It has the effect of limiting the amount of time that a credential leak can lead to exploit. The focus is on long-term undiscovered compromise using valid credentials. If an attack is not discovered, and the credentials are never changed, the attacker might have access for years. If you're worried about something like corporate espionage, this mitigation is simple and minimal effort.…
I argue that most compromises are effectively instantaneous. There’s usually little value in being a persistent threat when it takes only a moment to, for example, dump a database or an IMAP folder. Forcing rapid rotations just encourages people to choose weak passwords or store them on post it notes on their screen.
One of my employers had the Chinese in their networks for years. We all dutifully changed our passwords every 90 days and it made no difference at all to the Chinese persistence.
Re: First-ever DNSSEC root key rollover
#39Earlier quoted context omitted.
It's not a good thing. To a first approximation 0% of the mainstream public Internet relies on DNSSEC, so using a DNSSEC-validating resolver will on net get you only new outages; not any additional security, even at the margin. It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and…
You can't have DNSSEC outages if no-one is validating DNSSEC. So either there are outages, but a little extra security, or no extra security, but no outages, either.
Re: First-ever DNSSEC root key rollover
#40This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time! An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, if you scr…
Big five tech giants aren't playing, and I don't know any bank domains, but it's not hard to find names: cloudflare.com verisign.com comcast.net *.gov Every time dnssec shows up there's a tptacek comment crapping on the medium. are you using google alerts or something? what were your consulting fees for this service?
I know, right? Glad I’m not the only one to notice…