Live data from Hacker News

DNSSEC disruption affecting .de domains – Resolved

status.denic.de

381–390 of 440 posts

Re: DNSSEC disruption affecting .de domains – Resolved

#381

Cloudflare has now disabled DNSSEC validation on their 1.1.1.1 resolver: https://www.cloudflarestatus.com/incidents/vjrk8c8w37lz

We only disabled SSL on all the websites in one country for a little bit.. I'm sure those credit card numbers were perfectly safe over the wire

That comparison really makes the contrast clear: losing TLS would’ve put millions of people either into full downtime or immediately at significant risk (you can’t uncapture data). Losing DNSSEC, however, placed no one at risk and improved uptime.

There’s a reason why one of the two has roughly 10% adoption after three decades and the other is high 90-something percent.

Re: DNSSEC disruption affecting .de domains – Resolved

#382

.de TLD is online. DNS working fine DNSSEC not working If using an open resolver, i.e., a shared DNS cache, e.g., third party DNS service such as Google, Cloudflare, etc., then it might fail, or it might not. It depends on the third party DNS provider https://datatracker.ietf.org/meeting/118/materials/slides-11...

[deleted]

Re: DNSSEC disruption affecting .de domains – Resolved

#383
post #236

Earlier quoted context omitted.

Presumably if LetsEncrypt goes down and stays down for a week, the sites that go down are the ones that see that their CA went down and at no point in the week take the option to get certs from a different CA?

I guarantee that there are a ton of sites out there not monitoring their certs.

Including Microsoft, Starlink, Github, Cisco:

* https://www.keyfactor.com/blog/2023s-biggest-certificate-out...

Re: DNSSEC disruption affecting .de domains – Resolved

#384
post #371

I must be early. There's not a single tptacek DNSSEC rant in this thread yet.

Perhaps its more fair to call it 'passionate'. That said, the last few dnssec posts that got traction, tptacek tends to be at least 20% of the comments alone (ex, 55/259), ignoring word count. Today seems calm

"When the enemy is making a false movement, we must take good care not to interrupt him." — some guy, you wouldn't have hear of him

Re: DNSSEC disruption affecting .de domains – Resolved

#385

Earlier quoted context omitted.

We only disabled SSL on all the websites in one country for a little bit.. I'm sure those credit card numbers were perfectly safe over the wire

They didn't disable SSL you dingus.

it was an analogy to try highlighting how silly "security" is when it's opt-in and any intermediary can just disable it

Re: DNSSEC disruption affecting .de domains – Resolved

#386

Earlier quoted context omitted.

Nobody was taking credit cards online then. Your telnet sessions were easily sniffed, however.

Not in '94, sure. But a couple of years later it was common and SSL was still uncommon, for a bunch of reasons, and also everyone was storing the card numbers in plaintext on their servers too. Telnet was sniffed. IRC was being sniffed and logged.

Yes, I worked on some early ecommerce sites. Often, we'd accept credit cards with SSL and then send them out with email (plain text SMTP) to the customer, for manual entry. Very secure.

Re: DNSSEC disruption affecting .de domains – Resolved

#387
post #350

Earlier quoted context omitted.

As the CPU/RAM resources to run an authoritative-only slave nameserver for a few domains are extremely minimal (mine run at a unix load of 0.01), it's a very wise idea to put your ns3 or something at a totally different service provider on another continent . It costs less than a cup of coffee per month.

For a very long time, the computer club I was in operated a DNS server on a Pentium 75MHz and after the last major hardware upgrade it had a total of 110MB RAM memory and 2G disk space. It worked great except that before the upgrade it tended to run out of ram whenever there was a Linux kernel update, a problem we solved forever by populating all the ram slots with the maximum that the motherboard could handle to tha…

Did you populate the motherboard with the most it could handle, or the most you could assemble from a box of assorted sticks?

Otherwise, 110MB would hint at a fascinating engineering culture at the motherboard manufacturer.

Re: DNSSEC disruption affecting .de domains – Resolved

#388

Looks like a DNSSEC issue, not a nameserver outage. Validating resolvers SERVFAIL on every .de name with EDE: RRSIG with malformed signature found for a0d5d1p51kijsevll74k523htmq406bk.de/nsec3 (keytag=33834) dig +cd amazon.de @8.8.8.8 works, dig amazon.de @a.nic.de works. Zone data is intact, DENIC just published an RRSIG over an NSEC3 record that doesn't validate against ZSK 33834. Every validating resolver therefor…

So a single configuration mistake in a single place wiped out external reachability of a major economy. It happened in the evening local time and should be fixable, modulo cache TTLs, by morning. This will limit the blast radius somewhat. Still, at this level, brittle infrastructure is a political risk. The internet's famous "routing around damage" isn't quite working here. Should make for an interesting post mortem.

... wiped out external reachability of a major economy ...

internal reachability (from Germany to .de domains), too... :-)))

Re: DNSSEC disruption affecting .de domains – Resolved

#389
post #238

Earlier quoted context omitted.

denic is the single source of truth for zones under .de. The only problem with DNSSEC here is that it's complex.

A complex thing where making a mistake makes your domains drop off the internet seems like a pretty big "only problem".

There is no more complexity other than what is inherent to the task.

Re: DNSSEC disruption affecting .de domains – Resolved

#390
post #359
post #356

Earlier quoted context omitted.

Given how amateurish German IT operations is, there is no guarantee whatsoever there will be a post-mortem nor whether it then will make it out under 3-6 months with all the necessary approvals.

Bla bla, always easy to rant... https://blog.denic.de/denic-informiert-uber-die-behebung-der... "Die Störung ist inzwischen behoben und alle Systeme laufen wieder stabil. Die genaue Ursache wird derzeit noch analysiert. Sobald belastbare Erkenntnisse vorliegen, wird DENIC diese transparent zur Verfügung stellen." translation: ‘The disruption has now been resolved and all systems are running smoothly again. The exact…

Also always easy to announce "Sobald belastbare Erkenntnisse vorliegen, wird DENIC diese transparent zur Verfügung stellen." and then remain silent until the media forgets about the incident and never actually publish anything.
Post reply on HN