3 ms·
> Not if the root of trust is secured by a proof-of-work blockchain https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoculture https://tonyarcieri.com/
by CiPHPerCoder 6y ago
> Not if the root of trust is secured by a proof-of-work blockchain
https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoculture https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoc...
https://paragonie.com/blog/2017/07/chronicle-will-make-you-question-need-for-blockchain-technology https://paragonie.com/blog/2017/07/chronicle-will-make-you-q...
> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605 https://tools.ietf.org/html/rfc6605
First: That's a big "if". Lots of RSA legacy support.
Furthermore, ECDSA is so bad that Ed25519 and Ed448 are even coming to FIPS 186-5 later this year.
Citing ECDSA adoption in DNSSEC doesn't make as strong of a case as you might think.
- dane-pgp 6y agoFor context, some statistics: "Currently [2018], in more than 90% of cases if a user passes DNS queries to a resolver that performs DNSSEC validation of an RSA digital signature the same resolver will also perform DNSSEC validation of ECDSA P-256 digital signatures." https://blog.apnic.net/2018/08/23/measuring-ecdsa-in-dnssec-an-update/ https://blog.apnic.net/2018/08/23/measuring-ecdsa-in-dnssec-... "Since the second quarter of 2019 [to the first quarter of 2020], the population of [strict DNSSEC] validating users has risen from 12% to 22%, close to doubling. At the same time, the proportion of [non-strict DNSSEC validating] users has risen from 5% to 10%." https://blog.apnic.net/2020/03/02/dnssec-validation-revisited/ https://blog.apnic.net/2020/03/02/dnssec-validation-revisite...