4 ms·
DNSSEC you say? https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
by dependenttypes 7y ago
DNSSEC you say? https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- egberts1 7y agoI stopped midway down the first paragraph.
- caymanjim 7y agoThat was written by a prolific anti-DNSSEC campaigner active here on HN. I don't understand the system well enough to critique it, but between that post and various comments on HN, I've stopped assuming that DNSSEC is a universal good thing. Before I recently hardened my own email server and had to jump through all the hoops to get DANE working, I thought that DNSSEC was actually DNS-over-TLS with some sort of chain of trust back to the authoritative DNS server, and was surprised to learn that it was none of those things. I'm still going to use it but I'm not going to evangelize it the way I would if it actually provided encryption and trust.
- alwillis 7y agoI'm still going to use it but I'm not going to evangelize it the way I would if it actually provided encryption and trust. It was never supposed to encrypt lookup; that was mostly a disingenuous strawman argument from the usual suspects. It does provide a chain of trust. By using the public key published in your zone, a validating resolver checks the digital signatures from the root to your zone. It’s no different than when a browser checks the digital signatures on a certificate that’s signed by an intermediate certificate that was signed by a root certificate. For authentication and trust purposes, every resource record in a DNSSEC-signed zone is cryptographically signed and validating resolvers--Unbound, Knot Resolver, BIND--confirm them.