6 ms·
Why is there no love for DNSSEC and DANE?
by ratiolat 8y ago
Why is there no love for DNSSEC and DANE?
- LeonM 8y agoLook at the post history of tptacek. The guy really, really dislikes DNSSEC and uses every opportunity to rant about it. I have to agree that DNSSEC has its flaws, but tptacek can be a bit extreme about it.
- subway 8y agoI had to stop following him on other media due to the broken record nature of his complaints against dnssec :-/ It sucks to have to start tuning out useful bits because they're so often accompanied by tired rants.
- tptacek 8y agoI'm sorry. To better serve you, this call may be recorded for customer service purposes. At the time of this call, your current balance for services is... $0.00. Your next bill will be due... May... 1... 2019. So that I can properly route your call, please select from the following options. Press 1 for "change what Thomas says online to suit your personal preferences". Press 2 for billing. Press 3 for changes to your service. For all other inquiries, please remain on the line and an associate will be with you shortly.
- kortilla 8y agoOne of the best things to do when people tell you they followed you for your interesting thoughts but had to stop because of one thing you constantly rant about, the best response is definitely snark. The only way you could have appeared more obvious and self-centered is if you had provided materials about why DNSSEC sucks.
- deleted 8y ago[deleted]
- thanksDr 8y agoDear Thomas, Never change. Sincerely, Your fans
- lvh 8y agoAre there any other specs that ICANN tells everyone to deploy that regularly take down entire TLDs, DNS providers, and occasionally an entire RIR? [0]: https://www.icann.org/news/announcement-2019-02-22-en https://www.icann.org/news/announcement-2019-02-22-en [1]: https://ianix.com/pub/dnssec-outages.html https://ianix.com/pub/dnssec-outages.html (Disclaimer: I work with 'tptacek but I agree with him because he's right not because I have to ;-))
- subway 8y agoYou can be right about something without bringing it up every chance you get, despite it only having a vague relation to any topic being discussed.
- tptacek 8y agoAvoiding DNSSEC is literally, in the literal sense of the word literally, the primary motivation for MTA-STS. The relationship to this thread is not vague. (Source: the section of the RFC that says the primary motivation of MTA-STS is to ensure transport security when deployment of DNSSEC is undesirable or impractical.)
- tptacek 8y agoThis is a super irritating thing to say. I do in fact hate DNSSEC (nobody who pays any attention to me could have missed that fact and I don't hide it). But I "rant" about it on threads about DNS security, which is what you're seeing in my comment history. DNSSEC is small fraction of what I talk about on HN, but DNS security has been a somewhat hot topic in the past week. When I "rant" about DNSSEC and stop seeing people say "huh, what's wrong with DNSSEC?" as if they were unfamiliar with its problems, that will be my cue to stop "ranting" about it. The comment you're responding to is just such a statement, and you responded to it not with information but with a personal attack.
- deleted 8y ago[deleted]
- LeonM 8y ago> The comment you're responding to is just such a statement, and you responded to it not with information but with a personal attack. You (and korethr) are right, I should have written a more constructive reply. For that, I want apologize.
- korethr 8y agoI think that's a bit of an unfair characterization of tptacek's stance. Make no mistake, he does hate it, and does post against it when he can, but instead of (implicitly) painting him as (unreasonably) extreme about it, why not do something like link to his essay[1] on the topic, and let the GP inform themselves and come to their own conclusion? (like so) 1. https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- tptacek 8y agoGoogle [against dnssec].