Live data from Hacker News

Russian TLD .RU fails DNSSEC validation

dnsviz.net

1–10 of 24 posts

Re: Russian TLD .RU fails DNSSEC validation

#5
post #4

I'm not familiar with DNSSEC. What sis the impact of this? Do web pages fail to load or is it just some security warning? Also was this just someone failing to update a cert in time or is this some sort of hack?

If you're using DNSSEC-validating resolver servers (many of the popular ones are), then presumably all the signed names in .RU fell off the Internet completely, as if they never existed, for the duration of the outage.

Re: Russian TLD .RU fails DNSSEC validation

#6
post #4

I'm not familiar with DNSSEC. What sis the impact of this? Do web pages fail to load or is it just some security warning? Also was this just someone failing to update a cert in time or is this some sort of hack?

Basically, all ru. TLD became failing for all dns resolvers that use DNSSEC (which is the most of them)

As user, I am unable to visit any pages on .ru domains, as their IP would not resolve.

Reason is highly likely mistake (human side) in signing procedure, not something time- or hack- related.

Someone is most likely CC for TLD RU, aka АНО КЦНДСИ, official registry of .ru TLD.

Re: Russian TLD .RU fails DNSSEC validation

#8
post #7
post #3

That was scary. Fixed at about 16:55 UTC, total about 1hr of downtime.

The badly signed records are still there in various provider's DNS caches as of now. 8.8.8.8 and 9.9.9.9 in the Philippines are still affected - cannot resolve .ru domains.

Yeah, I think major Russian providers just flushed caches by hand, as rollout was by-region, which is not smooth nor simultaneous

EDIT: rollout in some very large telecom here is still in progress, by region.

Re: Russian TLD .RU fails DNSSEC validation

#10
As a side question: am I correct in reading this to imply that the two "leaf" keys here are both RSA 1024 keys? RSA 1024 has been considered within nation-state capabilities for well over a decade, and NIST has explicitly discouraged them for DNSSEC for close to a decade[1].

I can understand not using larger RSA key sizes for framing reasons, but what is stopping the DNSSEC ecosystem from using ECC?

[1]: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...

Post reply on HN