Live data from Hacker News

DNSSEC KSK rollover breaks DNS resolution for .nz domains

status.internetnz.nz

1–10 of 181 posts

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#6

If a safety upgrade to driving a car made people crash their cars more, you'd call that a bug. For DNS it's a feature called DNSSEC.

Your analogy would only be valid for a bug that made impersonating a site easier somehow, which this one didn't.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#8
post #4

If a safety upgrade to driving a car made people crash their cars more, you'd call that a bug. For DNS it's a feature called DNSSEC.

if your browser ignored all certificate errors, I guess you'd call that a feature?

If your browser ignored all certificate errors, you'd have a real security problem. That's not at all the case for DNSSEC: it's possible that all of the DNSSEC root keys could hit Pastebin and nobody would really need to be paged.

Re: DNSSEC KSK rollover breaks DNS resolution for .nz domains

#10
post #7

I hope the situation gets resolved swiftly, and lessons learned from this incident can contribute to stronger and more reliable DNSSEC practices in the future.

The root KSK rollover had to be postponed twice, for several years, because of operational problems pulling this off in the US. It's difficult to do because the nature of the DNS makes it difficult. The utility of DNSSEC is so marginal that it's kind of sad that you're right, and that engineers are gradually getting better doing this hard, stupid thing.
Post reply on HN