Live data from Hacker News

deSEC – Free Secure DNS

desec.io

31–40 of 59 posts

Re: deSEC – Free Secure DNS

#31

Earlier quoted context omitted.

> We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. I mean, if your definition of "affordable" is free, then sure. But for the record there are other affordable EU suppliers who do DNSSEC: - Bunny DNS[0] is "free" – i.e. only subject to their minimum $1/month account spend fee. - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` re…

I happen to run an affordable EU supplier who does DNSSEC, and also AXFR (incoming and outgoing). I offer a free plan from time to time, but not at the moment to preserve resources for paying customer. https://www.ptrdns.net/

Are you aware that the child zone A(AAAA) records for danube.ns.ptrdns.net differs from the parent zone A(AAA) glue records for danube.ns.ptrdns.net?

Looks like it's the glue records that point to the actual server?

Re: deSEC – Free Secure DNS

#33
post #14

We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.

DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions. https://sockpuppet.org/blog/2015/01/15/against-dnssec/

Such as? And do those solve the same thing? The post lists 8 headlines why it should be abolished.

Re: deSEC – Free Secure DNS

#34
post #30
post #14

Earlier quoted context omitted.

DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions. https://sockpuppet.org/blog/2015/01/15/against-dnssec/

Rebuttal: https://easydns.com/blog/2015/08/06/for-dnssec/ >

That rebuttal held water 10 years ago, but fortunately we have made a lot of advancements since then.

DNSSEC was a solution trying to solve the problem of DNS security while still maintaining transparency for DNS operators to spy on queries. At the time, passive DNS was one of the tent poles of tracking malware and responding to security incidents.

We have since committed entirely to transport security in the form of DoH and friends. It solves the vast majority of problems we actually have.

Re: deSEC – Free Secure DNS

#35
I literally just switched away from Hurricane Electric to deSEC. The only real issue that I had with HE, but it's a big one, is that they don't allow wildcard CNAMEs. I consider that important for the security of some sensitive endpoints that I have no choice but to expose publicly. Those endpoints are well protected with 2FA and heavily monitored, but I wanted to be able to use randomized subdomains to at least have some obfuscation on top.

Re: deSEC – Free Secure DNS

#36

We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.

> We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. I mean, if your definition of "affordable" is free, then sure. But for the record there are other affordable EU suppliers who do DNSSEC: - Bunny DNS[0] is "free" – i.e. only subject to their minimum $1/month account spend fee. - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` re…

We have a support ticket at Bunny that has been open for months precisely because they don’t provide state-of-the-art DNSSEC. We had to move to another provider, as we have a deadline to comply with at the end of this month. I don’t know what the issue is off the top of my head.

Netnod.se uses a DNSKEY that is too small on their main domain.

Rcodezero.at might indeed be something. Thanks.

We donate to deSEC, so it’s not free for us.

Re: deSEC – Free Secure DNS

#37
post #14

Earlier quoted context omitted.

DNSSEC support is an anti-feature, it is dead/dying and the faster we can unburden ourselves from it the faster we can move on to better solutions. https://sockpuppet.org/blog/2015/01/15/against-dnssec/

So DNS should be open to MITM attackers?

Even with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/

Re: deSEC – Free Secure DNS

#38
post #11

I signed up and saw they only allowed a single subdomain for DDNS, with docs saying to contact support if you needed more. I emailed asking for just 1 more subdomain and support told me that for my usecase I should just use CloudFlare. So I did. No silly miniscule restrictions.

I had this issue with cloudns and a single record with an IPv4 and IPv6 address. They only allowed one free ddns record which covered exactly one protocol. On top of that, they added records to resolve unknown names for advertising purposes.

I get that it costs money to run a DNS service but it seems like it should be a lot cheaper at scale than a lot of companies are providing.

Re: deSEC – Free Secure DNS

#39
I switched to deSEC because they allow you to create tokens for DNS-01 validation which are tightly scoped to a single subdomain. This means I have a VM running "service1.foo.example.com" which is not publicly available but can still get certs from letsencrypt, but with a token that can't be used to issue certs for other domains.

It works great!

Re: deSEC – Free Secure DNS

#40
post #19

When I last tried deSEC, the service was reliable and well worth the price of admission, but the web UI and API were both quite rough, and propagation tended to be quite slow. It was annoying to do an ACME DNS01 challenge on it, for example. IIRC, the API didn't have a complete set of replace/edit endpoints, so even DNSControl ( https://github.com/DNSControl/dnscontrol ) would leave records nonexistent for a while wh…

> well worth the price of admission

A strange thing to say about something that is free

Post reply on HN