Live data from Hacker News

DNSSEC disruption affecting .de domains – Resolved

status.denic.de

311–320 of 440 posts

Re: DNSSEC disruption affecting .de domains – Resolved

#311

Earlier quoted context omitted.

How simple sysadmin was in 1994 with no cryptography on any protocol. Everything could be easily MITM'd. Your credit card number would get jacked left and right in the 90s.

Nobody was taking credit cards online then. Your telnet sessions were easily sniffed, however.

Not in '94, sure. But a couple of years later it was common and SSL was still uncommon, for a bunch of reasons, and also everyone was storing the card numbers in plaintext on their servers too.

Telnet was sniffed. IRC was being sniffed and logged.

Re: DNSSEC disruption affecting .de domains – Resolved

#312

Earlier quoted context omitted.

So a single configuration mistake in a single place wiped out external reachability of a major economy. It happened in the evening local time and should be fixable, modulo cache TTLs, by morning. This will limit the blast radius somewhat. Still, at this level, brittle infrastructure is a political risk. The internet's famous "routing around damage" isn't quite working here. Should make for an interesting post mortem.

> The internet's famous "routing around damage" ...is only for Pentagon networks and military stuff. It's not for us normal people. (We get Cloudflare and FAANG bullshit instead.)

This is actually startlingly true.

Every FAANG company has their own fiber backbone. Why invest the internet that everyone uses when you can invest in your own private internet and then sell that instead?

Re: DNSSEC disruption affecting .de domains – Resolved

#313
post #208

Earlier quoted context omitted.

I am reminded of the warning that zonemaster gives about putting your domain name servers on a single AS, as is common practice for many larger providers. A lot of people do not want others to see this as a problem since a single AS is a convenient configuration for routing, but it has the downside of being a single point of failure. Building redundant infrastructure that can withstand BGP and DNS configuration mista…

On Google cloud it's always four nameservers like ns-cloud-c1.googledomains.com ns-cloud-c2.googledomains.com ns-cloud-c3.googledomains.com ns-cloud-c4.googledomains.com Would not make any sense to do four of them if it's a single AZ. Also, they are geo-aware and routed to your nearest region.

Are you conflating autonomous system (AS) with availability zone (AZ)?

Re: DNSSEC disruption affecting .de domains – Resolved

#314

Earlier quoted context omitted.

Germany appears to depend on it. Virtually none of North America does. I'm pretty satisfied with how this whole thing shook out!

You're wrong. Both .com and .net are signed (`dig RRSIG com.`), and if they screw up, then all the com/net zones will become inaccessible.

Sssshh, don't give Verisign any bad ideas!

Re: DNSSEC disruption affecting .de domains – Resolved

#315

Earlier quoted context omitted.

So a single configuration mistake in a single place wiped out external reachability of a major economy. It happened in the evening local time and should be fixable, modulo cache TTLs, by morning. This will limit the blast radius somewhat. Still, at this level, brittle infrastructure is a political risk. The internet's famous "routing around damage" isn't quite working here. Should make for an interesting post mortem.

fail-closed protocols have introduced some brittleness. A HTTP 1.0 server from 1999 probably still can service visitors today. A HTTPS/TLS 1.0 server from the same year wouldn't.

I think I see the point you're making here and I agree.

There is designing something to be fail-closed because it needs to be secure in a physical sense (actually secure, physically protected), and then there's designing something fail-closed because it needs to be secure from an intellectual sense (gatekept, intellectually protected). While most of the internet is "open source" by nature, the complexity has been increased to the point where significant financial and technical investment must be made to even just participate. We've let the gatekeepers raise the gates so high that nobody can reach them. AI will let the gatekeepers keep raising the gates, but then even they won't be able to reach the top. Then what?

I think the point you're trying to make, put another way is in the context of "availability" and "accessibility" we've compromised a lot of both availability and accessibility in the name of security since the dawn of the internet. How much of that security actually benefits the internet, and how much of that security hinders it? How much of it exists as a gatekeeping measure by those who can afford to write the rules?

Re: DNSSEC disruption affecting .de domains – Resolved

#317

Earlier quoted context omitted.

Yeah it's only the third largest economy in the world

> Yeah it's only the third largest economy in the world You can both be the 3rd biggest economy in the world and still only be 1/10th of US+China GDPs combined. And only three companies in the Top 100 for Germany: https://companiesmarketcap.com/ Germany is the kingdom of the "mittelstand": many, many, many SMEs. Both GP and you are right: it's the 3rd largest economy in the world and yet it's simply not that big. htt…

> In other words: I expect this German DNS SNAFU to have 0.000000001% impact on the world's GDP this year.

126 trillion USD * 0.00000000001 = 1260USD

I'm pretty sure the impact was higher than that ;)

Re: DNSSEC disruption affecting .de domains – Resolved

#320

https://status.denic.de/ says "Partial Service Disruption" for DNS Nameservice now. EDIT: it says "Service Disruption" now

Even when every site in the world’s 3rd biggest economy goes down it’s still just a ‘Partial’ service disruption :D

Not every site, just the ones using DNSSEC. Clearly, denic.de was online, for instance.
Post reply on HN