Live data from Hacker News

For DNSSEC

blog.easydns.org

1–10 of 81 posts

Re: For DNSSEC

#6
post #4

Earlier quoted context omitted.

DNSSEC has several problems some of which is in the design, as tptacek likes to mention.

But what do you mean by "online signing" ?

One of the problems is that it exposed DNS zone information, and one of the reason it did that was it was designed to require signing only once and after that the private key didn't have to be used again until the zone info changes.

Re: For DNSSEC

#7
post #2

Personally I think a new DNSSEC2 based on for example online signing might be a good idea.

There is nothing stopping you from doing online signing with DNSSEC. FWIW, DNSSEC is on it's third major iteration, 2/3rds of the TLDs have deployed it, and major DNS service providers are getting into the act.

Re: For DNSSEC

#8
post #2

Personally I think a new DNSSEC2 based on for example online signing might be a good idea.

What do you mean?

Signing DNS records using a machine connected to the internet, instead of passing the zone files to an air-gapped signing machine over a sneakernet. Eventually, you run into the issue of updating the "offline" machine and many places just have an "online" machine that gets the zone files through a highly restricted interface.

Re: For DNSSEC

#9
post #6

Earlier quoted context omitted.

But what do you mean by "online signing" ?

One of the problems is that it exposed DNS zone information, and one of the reason it did that was it was designed to require signing only once and after that the private key didn't have to be used again until the zone info changes.

Are you talking about zone enumeration? That's covered in the article.

Re: For DNSSEC

#10
post #4

Earlier quoted context omitted.

What do you mean?

DNSSEC has several problems some of which is in the design, as tptacek likes to mention.

This post directly addresses each point that Ptacek raised in his "Against DNSSEC" blogpost and FAQ.
Post reply on HN