Live data from Hacker News

DNSSEC disruption affecting .de domains – Resolved

status.denic.de

241–250 of 440 posts

Re: DNSSEC disruption affecting .de domains – Resolved

#241
post #223

Earlier quoted context omitted.

Normally it should not have been, with cache and all, but that was the past... Think about what would happen the day that letsencrypt is borken for whatever reason technical or like having a retarded US leader and being located in the wrong country. Taken into account the push of letsencrypt with major web browsers to restrict certificate validities for short periods like only a few days...

Let's Encrypt has to be down for days before people begin to feel the pain. DNS is very different, it breaks stuff immediately everywhere.

No it doesn't. DNS breaks as soon as TTLs run out. It's your choice to set them so low that stuff breaks immediately.

Re: DNSSEC disruption affecting .de domains – Resolved

#242

Earlier quoted context omitted.

Germany isn't as big as you think.

Yeah it's only the third largest economy in the world

> Yeah it's only the third largest economy in the world

You can both be the 3rd biggest economy in the world and still only be 1/10th of US+China GDPs combined.

And only three companies in the Top 100 for Germany:

https://companiesmarketcap.com/

Germany is the kingdom of the "mittelstand": many, many, many SMEs.

Both GP and you are right: it's the 3rd largest economy in the world and yet it's simply not that big.

https://en.wikipedia.org/wiki/Mittelstand

In other words: I expect this German DNS SNAFU to have 0.000000001% impact on the world's GDP this year.

Re: DNSSEC disruption affecting .de domains – Resolved

#243
post #211

Earlier quoted context omitted.

Aged like a milk.

Oh, yeah, I'm sure feeling chastened right now. You got me.

Parmigianino-Reggiano is aged milk, so I'm not sure what people have against aged milk. Aged milk can be great

Re: DNSSEC disruption affecting .de domains – Resolved

#244

Earlier quoted context omitted.

DNS is a centralization risk, yes. Somehow we've decided this is fine. DNSSEC isn't the only issue - your TLD's nameservers could also be offline, or censored in your country.

Not really? .com and .net are still up If Let's Encrypt goes down, half of the Internet will become inaccessible in a week.

So it seems we need something like this [1] for IT infrastructure? ;)

[1] https://outerspaceinstitute.ca/crashclock/

Re: DNSSEC disruption affecting .de domains – Resolved

#245
post #211

Earlier quoted context omitted.

Aged like a milk.

Oh, yeah, I'm sure feeling chastened right now. You got me.

My poor fellow. You wrote about how something is a bad tool for a long list of serious reasons. Then it failed spectacularly because everybody decided to depend on it anyway - exactly what you were cautioning against. But somehow you have to respond to people who think you are the one who got it wrong! As a third party the whole affair gave me a good chuckle at least ;)

Re: DNSSEC disruption affecting .de domains – Resolved

#246
post #205

Earlier quoted context omitted.

If it turns out the DNSSEC issue was caused by threat actors, this downstream effect could very well have been the reason to do it.

It is indeed a bit sad that Cloudflare had to turn off DNSSEC completely. But I completely understand that they don't have a production-ready, tested path to override DNSSEC validation for only some domains.

[flagged]

Re: DNSSEC disruption affecting .de domains – Resolved

#247

Earlier quoted context omitted.

It's night. Somebody has to fill a form to approve night work first.

And then fax the form to the correct authority, so that the request is Official(tm).

Well at least that doesn't require functioning DNS. This time around, it in fact could not have been an email :)

Re: DNSSEC disruption affecting .de domains – Resolved

#248
post #245

Earlier quoted context omitted.

Oh, yeah, I'm sure feeling chastened right now. You got me.

My poor fellow. You wrote about how something is a bad tool for a long list of serious reasons. Then it failed spectacularly because everybody decided to depend on it anyway - exactly what you were cautioning against. But somehow you have to respond to people who think you are the one who got it wrong! As a third party the whole affair gave me a good chuckle at least ;)

Germany appears to depend on it. Virtually none of North America does. I'm pretty satisfied with how this whole thing shook out!

Re: DNSSEC disruption affecting .de domains – Resolved

#249
post #205

Earlier quoted context omitted.

It is indeed a bit sad that Cloudflare had to turn off DNSSEC completely. But I completely understand that they don't have a production-ready, tested path to override DNSSEC validation for only some domains.

[flagged]

It didn't originally say that. They added the clarification just a few minutes ago. The guidelines ask you not to ask people these kinds of questions, for what it's worth.

Re: DNSSEC disruption affecting .de domains – Resolved

#250
post #52
post #29

I just spent the better half of an hour to debug unbound and the pihole because I thought it's a me problem... Good news though, if you add domain-insecure: "de" to your unbound config everything works fine

I don't even enable DNSSEC in Unbound. There just isn't enough adoption yet for me to feel like I am missing out on something, yet . "Cloudflare Radar data shows 8.11% of domains are signed with DNSSEC, but only 0.47% of queries are validated end-to-end." [1] Zones I may care about: - Amazon.com: unsigned - My banks: unsigned - Hacker News: unsigned - Email that I do not host: unsigned - My power companies billing: u…

The Tranco list is an academic research project to generate a "top N zones" list. Here's the portion of the top 1000 that is signed:

https://dnssecmenot.fly.dev/

Post reply on HN