Live data from Hacker News

First-ever DNSSEC root key rollover

redhat.com

41–50 of 75 posts

Re: First-ever DNSSEC root key rollover

#41
post #13
post #8

What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did. I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?

The old key was hosted inside a proprietary appliance and can't be extracted. https://labs.ripe.net/Members/anandb/the-future-of-dnssec-at... https://labs.ripe.net/Members/anandb/dnssec-signer-migration """Our old Secure64 signers do not export their private keys. This means that in order to migrate to the new signers, we will have to perform a KSK roll-over."""

I'm pretty sure that's unrelated to the DNSSEC root key which is managed by IANA and not RIPE NCC. https://www.iana.org/dnssec

I'm guessing that's referring to signing the reverse DNS zones for their IP address allocations (193.in-addr.arpa for example) and it's just coincidentally timed with the DNSSEC root key rollover.

Re: First-ever DNSSEC root key rollover

#42
post #25
post #18

This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time! An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, if you scr…

Big five tech giants aren't playing, and I don't know any bank domains, but it's not hard to find names: cloudflare.com verisign.com comcast.net *.gov Every time dnssec shows up there's a tptacek comment crapping on the medium. are you using google alerts or something? what were your consulting fees for this service?

what were your consulting fees for this service?

Keep this ad hominem nonsense off HN, please.

Re: First-ever DNSSEC root key rollover

#43
post #13
post #8

What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did. I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?

The old key was hosted inside a proprietary appliance and can't be extracted. https://labs.ripe.net/Members/anandb/the-future-of-dnssec-at... https://labs.ripe.net/Members/anandb/dnssec-signer-migration """Our old Secure64 signers do not export their private keys. This means that in order to migrate to the new signers, we will have to perform a KSK roll-over."""

Isn’t that a good thing? You don’t want to be able to export keys from a HSM.

Re: First-ever DNSSEC root key rollover

#44

Earlier quoted context omitted.

I argue that most compromises are effectively instantaneous. There’s usually little value in being a persistent threat when it takes only a moment to, for example, dump a database or an IMAP folder. Forcing rapid rotations just encourages people to choose weak passwords or store them on post it notes on their screen.

And groups that value persistence (like APTs) rarely depend on passwords to provide it. Instead they map the environment and find a local vulnerability to exploit and create a place to hang out. One of my employers had the Chinese in their networks for years. We all dutifully changed our passwords every 90 days and it made no difference at all to the Chinese persistence.

Right. The classic is an email account is compromised, a forward to rule is added, and nobody ever notices. It’s a false sense of security if preventing persistence is the goal. Usually instantaneous access is going to be the most disastrous effect anyway.

Re: First-ever DNSSEC root key rollover

#45
post #18

This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time! An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, if you scr…

I seriously don't understand why you are so much against DNSSEC. Just about every HN article that involves DNS had one of your anti-DNSSEC rants in them.

Yes, we know DNSSEC has some flaws, but how is DNSSEC worse than the alternative, which is no zone signing at al?

> if you screw the deployment of DNSSEC up, sites vanish off the Internet.

If you screw up your TLS certificate, your site also vanishes off the internet, should we also give up on HTTPS then?

Re: First-ever DNSSEC root key rollover

#46
post #25

Earlier quoted context omitted.

Big five tech giants aren't playing, and I don't know any bank domains, but it's not hard to find names: cloudflare.com verisign.com comcast.net *.gov Every time dnssec shows up there's a tptacek comment crapping on the medium. are you using google alerts or something? what were your consulting fees for this service?

Every time dnssec shows up there's a tptacek comment crapping on the medium. I know, right? Glad I’m not the only one to notice…

For example Thomas likes Let's Encrypt but he's stuck with his narrative about how nothing uses DNSSEC. So when you point out that Let's Encrypt uses DNSSEC so this position makes no sense, Thomas will just pretend not to understand and refer you back to stuff he wrote many years ago about how nothing uses DNSSEC.

Re: First-ever DNSSEC root key rollover

#47
post #39
post #37

Earlier quoted context omitted.

You can't have DNSSEC outages if no-one is validating DNSSEC. So either there are outages, but a little extra security, or no extra security, but no outages, either.

Sure you can. Virtually no part of the web PKI takes advantage (or ever will take advantage) of DNSSEC. Having DNSSEC enabled on your domain will accomplish nothing for you. But: if you misconfigure DNSSEC, or fail to maintain it, your site will vanish from the Internet for the users that make the mistake of using DNSSEC-validating resolvers. You've gained no security, but you have gained additional outages.

Of course you gain security, but not in the HTTPS PKI sense. Not that long ago, somebody BGP hijacked Route 53 in order to serve up different IP's for specific domains. Had that domain been using DNSSEC, that attack would have failed for everyone using a validating resolver. That might not be a common attack, but it certainly grants security.

This could also help with "rogue" free wifi setups, that try to do something like that as well.

Re: First-ever DNSSEC root key rollover

#48
post #18

This was supposed to have happened a year ago (I think almost to the day?), but was aborted roughly a week before because nobody was confident the system would survive. Apparently it did this time! An unfortunate attribute of DNSSEC: nothing depends on it, to the extent that you could almost certainly post the root private keys on Pastebin and not cause a single mainstream site a problem. At the same time, if you scr…

> This was supposed to have happened a year ago

The article says that this HAPPENED a year ago:

> Note that this has been included for at least a year now [...]

Re: First-ever DNSSEC root key rollover

#49
post #36
post #30

Earlier quoted context omitted.

Maybe, but LetsEncrypt breaking would be fixed much faster than any other CA as it’s the only one where every user is automated. Contrast that with the legacy model and the emailed zip files of cert chains alone would flood the intertubes.

I like LetsEncrypt and wasn't trying to suggest it was a problem. I think the comparison between LetsEncrypt and DNSSEC is instructive; a LetsEncrypt confidentiality failure would be disastrous, and a DNSSEC confidentiality failure... actually wouldn't matter at all , unless someone out there is doing something really creative and dumb with the protocol.

This might actually be a bad point for letsencrypt. All the eggs are starting to be in the same basket.

Re: First-ever DNSSEC root key rollover

#50
post #9
post #8

What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did. I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?

The old one will presumably eventually be expired. That means someone who compromised the old one can't hang onto their access indefinitely.

If someone compromised the old one, it would be already catastrophic. Key rotations are mostly about compliance requirements and are also mostly rubbish.
Post reply on HN