4 ms·
The security is designed to guard against surreptitious access. Interested members of the public are welcome to attend ceremonies (availability on a first-come
by kijeda 10y ago
The security is designed to guard against surreptitious access. Interested members of the public are welcome to attend ceremonies (availability on a first-come first-served basis).
There are multiple redundant sites and backups of the keys, so an attack aimed at destroying a site should not alone be a problem. Even if all all sites and backups were destroyed, there is a window where a new key can be constructed (approximately between 3-6 months worth of operational zone-singing keys are prepared in advance for the root zone).
- CiPHPerCoder 10y agoOne window of vulnerability is the after-party where everyone with a piece of the signing key drinks cocktails together.
- kijeda 10y agoCeremony attendees don't leave with part of the signing key. Despite the folklore around these ceremonies that there are 7 people with "the keys to the Internet", those seven only retain a metal key that is used to access a safety deposit box in the ICANN/IANA facility, each of which contains a smart card of which there is an "m-of-n" configuration to activate HSMs containing the actual key.
- CiPHPerCoder 10y agoThanks for the correction. :)