Earlier quoted context omitted.
I've been in IT 30+ years, been running DNS, web servers, etc. since at least 1994. I haven't bothered with DNSSEC due to perceived operational complexity. The penalty for a screw up, a total outage, just doesn't seem worth the security it provides.
How simple sysadmin was in 1994 with no cryptography on any protocol. Everything could be easily MITM'd. Your credit card number would get jacked left and right in the 90s.
DNSSEC disruption affecting .de domains – Resolved
291–300 of 440 posts
Re: DNSSEC disruption affecting .de domains – Resolved
#292Earlier quoted context omitted.
I don't even enable DNSSEC in Unbound. There just isn't enough adoption yet for me to feel like I am missing out on something, yet . "Cloudflare Radar data shows 8.11% of domains are signed with DNSSEC, but only 0.47% of queries are validated end-to-end." [1] Zones I may care about: - Amazon.com: unsigned - My banks: unsigned - Hacker News: unsigned - Email that I do not host: unsigned - My power companies billing: u…
The Tranco list is an academic research project to generate a "top N zones" list. Here's the portion of the top 1000 that is signed: https://dnssecmenot.fly.dev/
Re: DNSSEC disruption affecting .de domains – Resolved
#293Earlier quoted context omitted.
Sounds like poor risk pooling. If that room crashed, we'd have nobody to fix this.
nation state actor picking right time to sabotage a tiny part of the key rotation process. on monday someone cut major fiber lines, on tuesday DENIC is failing. maybe someone is showing off?
Re: DNSSEC disruption affecting .de domains – Resolved
#294Earlier quoted context omitted.
Let's Encrypt has to be down for days before people begin to feel the pain. DNS is very different, it breaks stuff immediately everywhere.
No it doesn't. DNS breaks as soon as TTLs run out. It's your choice to set them so low that stuff breaks immediately.
Re: DNSSEC disruption affecting .de domains – Resolved
#295Re: DNSSEC disruption affecting .de domains – Resolved
#296Earlier quoted context omitted.
> Keeping key material secure for more than a decade while it's in active use is vastly more complex than keeping it secure for a month, until it rotates. Nope. Key material rotation is just circus when it's done for the sake of rotation. > For all we know, some ex-employee might be walking around with that KSK, theoretically being able to use it for god knows what for an another decade. Or maybe an employee has comp…
The point of rotation for these kinds of keys is that it limits the blast radius of what happens if an employee compromises such a key. This is sort of like how there are one or two die-hard PGP advocates who have come up with a whole Cinematic Universe where authenticated encryption is problematic ("it breaks error recovery! it's usually not what you want!") because mainstream PGP doesn't do it. Except here, it's th…
I'm just saying that rotating the key just in case someone compromised it is not a great idea. Doubly so if it's done infrequently enough for the operational experience to atrophy between rotations.
And yeah, I fully agree that anything surrounding the DNSSEC operations is a burning trash fire. It doesn't have to be this way, but it is.
Re: DNSSEC disruption affecting .de domains – Resolved
#297Earlier quoted context omitted.
You're wrong. Both .com and .net are signed (`dig RRSIG com.`), and if they screw up, then all the com/net zones will become inaccessible.
Virtually no zones under .com/.net are signed, which was the only point I was making. It has no adoption here.
DENIC screwed up the TLD itself, and .com/.net are just as susceptible.
Re: DNSSEC disruption affecting .de domains – Resolved
#298Earlier quoted context omitted.
The point of rotation for these kinds of keys is that it limits the blast radius of what happens if an employee compromises such a key. This is sort of like how there are one or two die-hard PGP advocates who have come up with a whole Cinematic Universe where authenticated encryption is problematic ("it breaks error recovery! it's usually not what you want!") because mainstream PGP doesn't do it. Except here, it's th…
I can see the periodic rotations used as a way to keep up the operational experience. This is indeed a valid reason, although it needs to be weighted against the increased risk of compromise due to the rotation procedure itself. I'm just saying that rotating the key just in case someone compromised it is not a great idea. Doubly so if it's done infrequently enough for the operational experience to atrophy between rot…
Re: DNSSEC disruption affecting .de domains – Resolved
#299Re: DNSSEC disruption affecting .de domains – Resolved
#300Earlier quoted context omitted.
>So a single configuration mistake in a single place wiped out external reachability of a major economy. And fuck nothing at all happened as a result.
Prove it? I’m sure many lifespans were lost to stress
We had a short discussion about migrating to .com, but decided risk != reward as no one would know the new tld
I assume there are a couple people working for denic who had a stressfull night..