Live data from Hacker News

DNSSEC disruption affecting .de domains – Resolved

status.denic.de

291–300 of 440 posts

Re: DNSSEC disruption affecting .de domains – Resolved

#291

Earlier quoted context omitted.

I've been in IT 30+ years, been running DNS, web servers, etc. since at least 1994. I haven't bothered with DNSSEC due to perceived operational complexity. The penalty for a screw up, a total outage, just doesn't seem worth the security it provides.

How simple sysadmin was in 1994 with no cryptography on any protocol. Everything could be easily MITM'd. Your credit card number would get jacked left and right in the 90s.

Nobody was taking credit cards online then. Your telnet sessions were easily sniffed, however.

Re: DNSSEC disruption affecting .de domains – Resolved

#292
post #52

Earlier quoted context omitted.

I don't even enable DNSSEC in Unbound. There just isn't enough adoption yet for me to feel like I am missing out on something, yet . "Cloudflare Radar data shows 8.11% of domains are signed with DNSSEC, but only 0.47% of queries are validated end-to-end." [1] Zones I may care about: - Amazon.com: unsigned - My banks: unsigned - Hacker News: unsigned - Email that I do not host: unsigned - My power companies billing: u…

The Tranco list is an academic research project to generate a "top N zones" list. Here's the portion of the top 1000 that is signed: https://dnssecmenot.fly.dev/

That's cool, ty for that. The only one I put credentials into is Amazon it is unsigned. [1] There probably needs to be a DNSSECv2 .vbis that reduces risk somehow to get more adoption.

[1] - https://dnssec-analyzer.verisignlabs.com/amazon.com

Re: DNSSEC disruption affecting .de domains – Resolved

#293

Earlier quoted context omitted.

Sounds like poor risk pooling. If that room crashed, we'd have nobody to fix this.

nation state actor picking right time to sabotage a tiny part of the key rotation process. on monday someone cut major fiber lines, on tuesday DENIC is failing. maybe someone is showing off?

Unironically yeah, we are at the level of weaponizable sophistication that this metaphorical dick waving you are suggesting is probably something that happens

Re: DNSSEC disruption affecting .de domains – Resolved

#294
post #223

Earlier quoted context omitted.

Let's Encrypt has to be down for days before people begin to feel the pain. DNS is very different, it breaks stuff immediately everywhere.

No it doesn't. DNS breaks as soon as TTLs run out. It's your choice to set them so low that stuff breaks immediately.

What do you recommend then? DNS doesn't usually change that often, but if you mess it up when it does, you're in for some pain if TTLs are high!

Re: DNSSEC disruption affecting .de domains – Resolved

#296

Earlier quoted context omitted.

> Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. Nope. Key material rotation is just circus when it's done for the sake of rotation. > For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade. Or maybe an employee has comp…

The point of rotation for these kinds of keys is that it limits the blast radius of what happens if an employee compromises such a key. This is sort of like how there are one or two die-hard PGP advocates who have come up with a whole Cinematic Universe where authenticated encryption is problematic ("it breaks error recovery! it's usually not what you want!") because mainstream PGP doesn't do it. Except here, it's th…

I can see the periodic rotations used as a way to keep up the operational experience. This is indeed a valid reason, although it needs to be weighted against the increased risk of compromise due to the rotation procedure itself.

I'm just saying that rotating the key just in case someone compromised it is not a great idea. Doubly so if it's done infrequently enough for the operational experience to atrophy between rotations.

And yeah, I fully agree that anything surrounding the DNSSEC operations is a burning trash fire. It doesn't have to be this way, but it is.

Re: DNSSEC disruption affecting .de domains – Resolved

#297

Earlier quoted context omitted.

You're wrong. Both .com and .net are signed (`dig RRSIG com.`), and if they screw up, then all the com/net zones will become inaccessible.

Virtually no zones under .com/.net are signed, which was the only point I was making. It has no adoption here.

Sure. But that was not the issue with .de, it has about the same level of DNSSEC adoption as .com

DENIC screwed up the TLD itself, and .com/.net are just as susceptible.

Re: DNSSEC disruption affecting .de domains – Resolved

#298

Earlier quoted context omitted.

The point of rotation for these kinds of keys is that it limits the blast radius of what happens if an employee compromises such a key. This is sort of like how there are one or two die-hard PGP advocates who have come up with a whole Cinematic Universe where authenticated encryption is problematic ("it breaks error recovery! it's usually not what you want!") because mainstream PGP doesn't do it. Except here, it's th…

I can see the periodic rotations used as a way to keep up the operational experience. This is indeed a valid reason, although it needs to be weighted against the increased risk of compromise due to the rotation procedure itself. I'm just saying that rotating the key just in case someone compromised it is not a great idea. Doubly so if it's done infrequently enough for the operational experience to atrophy between rot…

I'm glad we agree about DNSSEC, but the rationale I'm giving you for key rotation is the same reason we use short-lived secrets everywhere in modern cryptosystems. It's not controversial (except among Unix systems administrators).

Re: DNSSEC disruption affecting .de domains – Resolved

#299

Earlier quoted context omitted.

Probably the most common reason to use TLS is to check a box on a list of compliance rules. Is that bad?

Do browsers even load non-HTTPS sites anymore without a massive warning?

Yes, they do.

Re: DNSSEC disruption affecting .de domains – Resolved

#300

Earlier quoted context omitted.

>So a single configuration mistake in a single place wiped out external reachability of a major economy. And fuck nothing at all happened as a result.

Prove it? I’m sure many lifespans were lost to stress

As someone with oncall yesterday it was a fun experience, but you noticed quickly that everything .de was down and then it was just a waiting game.

We had a short discussion about migrating to .com, but decided risk != reward as no one would know the new tld

I assume there are a couple people working for denic who had a stressfull night..

Post reply on HN