Live data from Hacker News

In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

indico.dns-oarc.net

61–70 of 73 posts

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#61
post #31

Earlier quoted context omitted.

They were probably exaggerating but it’s well known that American agencies can and will extort whatever they need from any American company and the organisation wouldn’t even be legally allowed to disclose that it even happened through secrecy and gag orders.

“Well known” in conspiracy circles. You’re referring to national security letters and, no, those cannot compel “whatever they need”: it’s limited to release of transactional data, not payload: https://en.wikipedia.org/wiki/National_security_letter Part of why the news about MUSCULAR was so shocking was that the Buah-era NSA was attacking the fiber connections between American tech companies’ data centers, because the…

If that was shocking, put your rubber gloves on for this read:

https://en.m.wikipedia.org/wiki/2010s_global_surveillance_di...

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#62
post #52

Earlier quoted context omitted.

By making it hard just to hijack a crucial TLD and transfer it over to an potential adversary without the cooperation of multiple trusted parties? It seems to me this is DNSSEC working as designed, and being remarkably flexible in doing so. Sometimes things _should_ be difficult to do.

Yeah I hate that people can't acknowledge that friction is sometimes intentional. Not everything -should- be easy. For example I designed a system at a previous company that used Shamir's Secret Sharing to protect a very very important root key. We used an intermediate of this key for most operations but it came time to rotate it and folks were surprised by the ceremony involved in doing so. i.e the root key was decr…

> Not everything -should- be easy.

the entirety of .nz probably wouldn't agree with you when they had a 2 day outage due to a slight DNSSEC misconfiguration

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#63
post #62
post #52

Earlier quoted context omitted.

Yeah I hate that people can't acknowledge that friction is sometimes intentional. Not everything -should- be easy. For example I designed a system at a previous company that used Shamir's Secret Sharing to protect a very very important root key. We used an intermediate of this key for most operations but it came time to rotate it and folks were surprised by the ceremony involved in doing so. i.e the root key was decr…

> Not everything -should- be easy. the entirety of .nz probably wouldn't agree with you when they had a 2 day outage due to a slight DNSSEC misconfiguration

???

at best that means there's more need for practice, testing, better processes, and so on. it does not mean everything should be easy. (especially changes to a critical name authority.)

there's an argument that maybe .nz needs to spend more on this, delegate this, or accept a decreased security assurance, but that's definitely not true in general.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#65
post #26

It is shocking how few people understand how DNS works

It is shocking how few people understand how business works. If you think Cloudflare wants to be in the registrar business, not push their Anti DDoS stuff on a captive audience, I have a bridge to sell you.

How dare they sell their reliable and popular products at rates untouched by akamai and fastly.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#67
post #63
post #62

Earlier quoted context omitted.

> Not everything -should- be easy. the entirety of .nz probably wouldn't agree with you when they had a 2 day outage due to a slight DNSSEC misconfiguration

??? at best that means there's more need for practice, testing, better processes, and so on. it does not mean everything should be easy. (especially changes to a critical name authority.) there's an argument that maybe .nz needs to spend more on this, delegate this, or accept a decreased security assurance, but that's definitely not true in general.

if you read the post-mortem they did everything by the book

they made a small mistake, and .nz was down for 2 days as a result

of course the 95% of people that have competent ISPs that don't verify DNSSEC records were completely unaffected

there's a reason ALL major tech companies refuse to deploy it for their zones

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#68
post #7

Does this mean every GOV page will now have the "pretend security check" interstitial that litter just about every page now? How do you even describe it, it's like they are vandalising the internet.

What are you on? Site owners choose to enable those rooms.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#69
post #40

Earlier quoted context omitted.

yet another example of DNSSEC "adding value"

By making it hard just to hijack a crucial TLD and transfer it over to an potential adversary without the cooperation of multiple trusted parties? It seems to me this is DNSSEC working as designed, and being remarkably flexible in doing so. Sometimes things _should_ be difficult to do.

In how many instances over the last 10 years has a country code TLD for a country of New Zealand's size or greater been stolen? It doesn't make sense to talk about benefits without costs, and vice versa. Error-prone and dangerous security demands urgent problems. Is TLD hijack one of them? It is not.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#70
post #67
post #63

Earlier quoted context omitted.

??? at best that means there's more need for practice, testing, better processes, and so on. it does not mean everything should be easy. (especially changes to a critical name authority.) there's an argument that maybe .nz needs to spend more on this, delegate this, or accept a decreased security assurance, but that's definitely not true in general.

if you read the post-mortem they did everything by the book they made a small mistake, and .nz was down for 2 days as a result of course the 95% of people that have competent ISPs that don't verify DNSSEC records were completely unaffected there's a reason ALL major tech companies refuse to deploy it for their zones

Most, not all. Salesforce is a notable counterexample.
Post reply on HN