Live data from Hacker News

Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

cloudflare.com

111–112 of 112 posts

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#111
post #45

Earlier quoted context omitted.

Secure DNS allows a number of nice things that otherwise are a risk, such as trusting server SSH fingerprints without prompting on first use.

And to get that feature all you have to do is trust that the government that controls your TLD isn't going to fuck you. Because it's not like the USG would ever tamper with the DNS to further a policy goal, right? http://gizmodo.com/5936870/doj-seizes-domains-over-app-pirac...

So your entire argument against DNSSEC is that the US Government seized the domains of known "pirated" software distribution sites?

Re: Cloudflare Introduces Universal DNSSEC: Secure DNS for Your Domain

#112

Earlier quoted context omitted.

One of the flaws about talking with an overloaded term like "security". If even abstractly, something does not work, what's the point of arguing about its technical details? As you said before, DNSSEC is fine if you concede .com to the US government. This has already happened, we're just putting it in writing.

No, we have not already conceded TLS keys for sites in .COM to the USG.

Instead, the current CA system means we've conceded all TLS.
Post reply on HN