Earlier quoted context omitted.
I many days would an email take?
To a .de domain?
DNSSEC disruption affecting .de domains – Resolved
351–360 of 440 posts
Re: DNSSEC disruption affecting .de domains – Resolved
#352Earlier quoted context omitted.
It is not fine. Keeping key material safe is not a boolean between "permanently safe" and "leaks immediately". Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade.
> Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. Nope. Key material rotation is just circus when it's done for the sake of rotation. > For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade. Or maybe an employee has comp…
I'm a mere sysadmin and not a cybersecurity expert. But this is always something that leaves me torn.
On the one hand, yes, rotation periods for many/most credentials are long enough that you're not really de-risking yourself all that much.
On the other hand, doing regular rotations allows you to tighten up your threat model. A regularly-rotated credential allows you to say "I implicitly trust that this credential has not been compromised prior to the previous rotation."[0] Whereas, without credential rotation, you're saying "I implicitly trust that this credential has not been compromised ever."
The latter to me seems clearly like the inferior model. The question is just whether the cost-benefit pencils out. And that is obviously very situationally dependent. That calculus doesn't pencil out when dealing with user-owned passwords for instance (i.e. the costs of regular password rotation dominate the benefits of the improved threat model). Human limitations with memory and such are the main issue there. However, that doesn't apply to e.g. hypothetical sufficiently developed DNSSEC infrastructure. Does that calculus pencil out there? I don't know. But it seems plausible at least.
[0] Modulo attackers having been able to pivot into a persistent threat with a previously-compromised credential.
Re: DNSSEC disruption affecting .de domains – Resolved
#353Earlier quoted context omitted.
Let's Encrypt has to be down for days before people begin to feel the pain. DNS is very different, it breaks stuff immediately everywhere.
No it doesn't. DNS breaks as soon as TTLs run out. It's your choice to set them so low that stuff breaks immediately.
Re: DNSSEC disruption affecting .de domains – Resolved
#354Earlier quoted context omitted.
What do you recommend then? DNS doesn't usually change that often, but if you mess it up when it does, you're in for some pain if TTLs are high!
Not the one you're replying to, but I'd keep TTL high normally and lower it one TTL ahead of a planned change.
Re: DNSSEC disruption affecting .de domains – Resolved
#355Earlier quoted context omitted.
Presumably if LetsEncrypt goes down and stays down for a week, the sites that go down are the ones that see that their CA went down and at no point in the week take the option to get certs from a different CA?
Are there alternative CAs that are anywhere as easy to deal with as Lets encrypt?
Re: DNSSEC disruption affecting .de domains – Resolved
#356That postmortem should be a fun read, can't wait.
Re: DNSSEC disruption affecting .de domains – Resolved
#357Re: DNSSEC disruption affecting .de domains – Resolved
#358Earlier quoted context omitted.
Welp. I think can call it on DNSSEC now.
Probably the most common reason to use DNSSEC is to check a box on a list of compliance rules. And I don't think this will change anything for people who need DNSSEC for compliance.
Re: DNSSEC disruption affecting .de domains – Resolved
#359That postmortem should be a fun read, can't wait.
Given how amateurish German IT operations is, there is no guarantee whatsoever there will be a post-mortem nor whether it then will make it out under 3-6 months with all the necessary approvals.
https://blog.denic.de/denic-informiert-uber-die-behebung-der...
"Die Störung ist inzwischen behoben und alle Systeme laufen wieder stabil. Die genaue Ursache wird derzeit noch analysiert. Sobald belastbare Erkenntnisse vorliegen, wird DENIC diese transparent zur Verfügung stellen."
translation:
‘The disruption has now been resolved and all systems are running smoothly again. The exact cause is currently being investigated. As soon as reliable findings are available, DENIC will make them publicly available.’
Re: DNSSEC disruption affecting .de domains – Resolved
#360Earlier quoted context omitted.
Even when every site in the world’s 3rd biggest economy goes down it’s still just a ‘Partial’ service disruption :D
Not every site, just the ones using DNSSEC. Clearly, denic.de was online, for instance.