16 ms·
Yeti DNS Project
- _jomo 8y agoFrom RFC8483 [0] "Yeti DNS Testbed", which was published a few hours ago: > Yeti DNS is an experimental, non-production root server testbed that provides an environment where technical and operational experiments can safely be performed without risk to production root server infrastructure. In section 5 they publish experience with their IPv6-Only operation. For example: > There are reports of a notable packet drop rate due to the mistreatment of middleboxes on IPv6 fragments. One APNIC study reported that 37% of endpoints using IPv6-capable DNS resolvers cannot receive a fragmented IPv6 response over UDP. Or: > It was observed that Yeti-Root servers running Knot 2.0 would compress the zero-length label (the root domain, often represented as ".") using a pointer to an earlier example. Although legal, this encoding increases the encoded size of the root label from one octet to two; it was also found to break some client software -- in particular, the Go DNS library. Bug reports were filed against both Knot and the Go DNS library, and both were resolved in subsequent releases. 0: https://tools.ietf.org/html/rfc8483 https://tools.ietf.org/html/rfc8483
- orivej 8y ago> it was also found to break some client software -- in particular, the Go DNS library The issue for the curious: https://github.com/miekg/dns/issues/234 https://github.com/miekg/dns/issues/234
- LeonM 8y agoIf only I could prepare the Yeti project maintainers for the giant anti-DNSSEC rant that tptacek is going to post here...
- tptacek 8y agoWhy would I bother? These are the DNSSEC true believers, and in some cases the authors of the standard.
- hazz99 8y agoAs a total outsider, what is wrong with DNSSEC? Security extensions seem like a good idea, to the uninitiated. Are there any relevant links I should read?
- Abekkus 8y agoIf Thomas isn't responding I will. DNSSEC is an important idea, but not something a company's security department should be terribly worried about implementing just this minute. TLS will take care of most of what you need in that area. The most practical concern right now is that DNSSEC isn't even being honored by most clients, so even if you build a solution that you're comfortable with, it will be doing nothing to secure most of your customers' connections. If clients start using DNSSEC more in the future, you'll hear about it.
- pvg 8y agoA big part of his argument is that it's not, in fact, an important idea.
- Abekkus 8y agoCalling DNSSEC "worse than nothing" is the part where he overreaches, doesn't engage with valid counterarguments, and just calls his objectors Linux nerds, or true believers; yet he still gets upvoted by some quiet army.
- pvg 8y agohttps://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- auslander 8y agoWhat a rubbish.
- deleted 8y ago[deleted]
- auslander 8y agoSeems like all cool heads, not in 'Ban the DNSSEC' camp are flagged.