Live data from Hacker News

First-ever DNSSEC root key rollover

redhat.com

31–40 of 75 posts

Re: First-ever DNSSEC root key rollover

#31
post #29
post #4

Earlier quoted context omitted.

No, because nobody really depends on DNSSEC, so nothing will break: - https://ianix.com/pub/dnssec-outages.html - https://twitter.com/tqbf/status/772103926258671618

> because nobody really depends on DNSSEC That's not true. A lot of people use DNSSEC validating public resolvers like 1.1.1.1 and 8.8.8.8, especially on Android devices. I use DNSSEC on my personal domain, and when my zone-resigning cronjob fails, I notice pretty quickly, because the page really does fail to load in my browser.

Is that a good thing? That sounds like a pretty solid reason not to deploy DNSSEC.

Re: First-ever DNSSEC root key rollover

#32
post #17

But when will it be supported in Route53?

But why do you want it? DNSSEC and TLS cover much of the same use cases - except DNSSEC is worse. IIRC, it uses 1024bit RSA keys - which are large, and yet not particularly strong. It gives you very little flexibility - if you own example.com, you have to trust the root key and Verisign and whatever governments have authority over them and the only way out is to change to a different domain name. And what seemed like the most interesting technology enabled by DNSSEC (DANE) has no browser uptake (for good reason).

Re: First-ever DNSSEC root key rollover

#33
post #28
post #26

Earlier quoted context omitted.

Cloudflare and Verisign are no surprise; Cloudflare has a DNSSEC product, and Verisign is effectively one of the sponsors of the protocol. For what it's worth: Akamai does DNSSEC, too. Comcast is indeed DNSSEC-signed (how you know Comcast does DNSSEC is, as I said, they sort of infamously broke an HBO product launch with it). But, for instance: Verizon and AT&T are not!

Also first national bank I tried to look up, (actually don't know if that's what you mean by national bank) federalreserve.gov is using dnssec.

Sorry, I meant nationwide banking chains, like Bank of America. .GOV has, from years back, a mandate to adopt DNSSEC.

Re: First-ever DNSSEC root key rollover

#34
post #31
post #29

Earlier quoted context omitted.

> because nobody really depends on DNSSEC That's not true. A lot of people use DNSSEC validating public resolvers like 1.1.1.1 and 8.8.8.8, especially on Android devices. I use DNSSEC on my personal domain, and when my zone-resigning cronjob fails, I notice pretty quickly, because the page really does fail to load in my browser.

Is that a good thing? That sounds like a pretty solid reason not to deploy DNSSEC.

It's not a good thing. To a first approximation 0% of the mainstream public Internet relies on DNSSEC, so using a DNSSEC-validating resolver will on net get you only new outages; not any additional security, even at the margin.

It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and drives lock-in for them, and that governments cheerlead because it in theory grants control over all web crypto to them.

Re: First-ever DNSSEC root key rollover

#35
post #32
post #17

But when will it be supported in Route53?

But why do you want it? DNSSEC and TLS cover much of the same use cases - except DNSSEC is worse. IIRC, it uses 1024bit RSA keys - which are large, and yet not particularly strong. It gives you very little flexibility - if you own example.com, you have to trust the root key and Verisign and whatever governments have authority over them and the only way out is to change to a different domain name. And what seemed like…

Until rather recently, the root DNSSEC keys were RSA-1024, but the roots are now RSA-2048 (which is fine). But the rest of the DNSSEC PKI is positively littered with RSA-1024 keys (for instance: there's one in .COM).

Re: First-ever DNSSEC root key rollover

#36
post #30
post #24

Earlier quoted context omitted.

DNSSEC precedes its first RFC by several years; before that RFC, it was a DoD-funded project run by Trusted Information Systems. It's different today in a variety of ways, but the fundamental design decisions --- offline signers, authenticated denial --- date back to TIS and the USG. If LetsEncrypt broke, there would be absolute chaos across the Internet.

Maybe, but LetsEncrypt breaking would be fixed much faster than any other CA as it’s the only one where every user is automated. Contrast that with the legacy model and the emailed zip files of cert chains alone would flood the intertubes.

I like LetsEncrypt and wasn't trying to suggest it was a problem. I think the comparison between LetsEncrypt and DNSSEC is instructive; a LetsEncrypt confidentiality failure would be disastrous, and a DNSSEC confidentiality failure... actually wouldn't matter at all, unless someone out there is doing something really creative and dumb with the protocol.

Re: First-ever DNSSEC root key rollover

#37
post #34
post #31

Earlier quoted context omitted.

Is that a good thing? That sounds like a pretty solid reason not to deploy DNSSEC.

It's not a good thing. To a first approximation 0% of the mainstream public Internet relies on DNSSEC, so using a DNSSEC-validating resolver will on net get you only new outages; not any additional security, even at the margin. It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and…

You can't have DNSSEC outages if no-one is validating DNSSEC. So either there are outages, but a little extra security, or no extra security, but no outages, either.

Re: First-ever DNSSEC root key rollover

#38

Earlier quoted context omitted.

> if this actually has any effect It has the effect of limiting the amount of time that a credential leak can lead to exploit. The focus is on long-term undiscovered compromise using valid credentials. If an attack is not discovered, and the credentials are never changed, the attacker might have access for years. If you're worried about something like corporate espionage, this mitigation is simple and minimal effort.…

I argue that most compromises are effectively instantaneous. There’s usually little value in being a persistent threat when it takes only a moment to, for example, dump a database or an IMAP folder. Forcing rapid rotations just encourages people to choose weak passwords or store them on post it notes on their screen.

And groups that value persistence (like APTs) rarely depend on passwords to provide it. Instead they map the environment and find a local vulnerability to exploit and create a place to hang out.

One of my employers had the Chinese in their networks for years. We all dutifully changed our passwords every 90 days and it made no difference at all to the Chinese persistence.

Re: First-ever DNSSEC root key rollover

#39
post #37
post #34

Earlier quoted context omitted.

It's not a good thing. To a first approximation 0% of the mainstream public Internet relies on DNSSEC, so using a DNSSEC-validating resolver will on net get you only new outages; not any additional security, even at the margin. It's a failed protocol that a subset of Linux nerds cheerlead because any classic Internet protocol + "SEC" must be cool, that companies like Cloudflare cheerlead because it's complicated and…

You can't have DNSSEC outages if no-one is validating DNSSEC. So either there are outages, but a little extra security, or no extra security, but no outages, either.

Sure you can. Virtually no part of the web PKI takes advantage (or ever will take advantage) of DNSSEC. Having DNSSEC enabled on your domain will accomplish nothing for you. But: if you misconfigure DNSSEC, or fail to maintain it, your site will vanish from the Internet for the users that make the mistake of using DNSSEC-validating resolvers. You've gained no security, but you have gained additional outages.

Re: First-ever DNSSEC root key rollover

#40
post #25
post #18

This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time! An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, if you scr…

Big five tech giants aren't playing, and I don't know any bank domains, but it's not hard to find names: cloudflare.com verisign.com comcast.net *.gov Every time dnssec shows up there's a tptacek comment crapping on the medium. are you using google alerts or something? what were your consulting fees for this service?

Every time dnssec shows up there's a tptacek comment crapping on the medium.

I know, right? Glad I’m not the only one to notice…

Post reply on HN