4 ms·
Not arguing either which way, but was curious and did a few names off the top of my head: yes: Cloudflare no: easyDNS, Google, Apple, Facebook, Wikipedia/medi
by Operyl 5y ago
Not arguing either which way, but was curious and did a few names off the top of my head:
yes: Cloudflare
no: easyDNS, Google, Apple, Facebook, Wikipedia/media, Twitter, Reddit
I knew DNSSEC wasn't well-deployed, but I didn't realize how little.
- tptacek 5y agoKeep going! It gets funnier as you keep looking. (For those playing the home game, it's just `host -t ds <domain>` to check for DNSSEC; `host -t ds salesforce.com` is what it looks like when you do have DNSSEC enabled.) To save some trouble: other companies that haven't enabled DNSSEC include Mozilla, Netflix, Stripe, Bank of America, Citigroup, Microsoft, Adobe, Oracle, Amazon, Intel, IBM, Atlassian, Coinbase, Equinix, Datadog, Twilio, Ebay, and Shopify. Speaking of Salesforce: the chatter is that the real reason Slack enabled DNSSEC briefly is because Salesforce --- their parent company --- already had it enabled, presumably for the same bogus FedRAMP reason. Cloudflare is probably the most notable DNSSEC user. But then: Cloudflare sells DNSSEC services.
- tzs 5y agoSome more without: mit.edu, harvard.edu, ucla.edu, usc.edu Some more with: berkeley.edu, stanford.edu, caltech.edu (Dammit...now I'm curious about what is actually in those records, because the 'host -t ds' output for all of them is 3 apparently decimal numbers, a long hex string, and a short hex strings except for Caltech's, which is missing the final short hex string).
- defanor 5y ago> (Dammit...no I'm curious about what is actually in those records, because the 'host -t ds' output for all of them is 3 apparently decimal numbers, a long hex string, and a short hex strings except for Caltech's, which is missing the final short hex string). Those are DS records, what host(1) prints is their presentation format [1]: > The presentation format of the DS record consists of three numbers (key tag, algorithm, and digest type) followed by the digest itself presented in hex Digest type 1 (as for caltech.edu) is for SHA-1 [2], type 2 (as for stanford.edu) is for SHA-256 [3]. So caltech.edu just uses a shorter hash, and whitespace is allowed in the presentation [4]. FWIW, one can also check and verify that/whether DNSSEC works with delv(1) (similar to dig(1), but with validation). [1] https://datatracker.ietf.org/doc/html/rfc3658#section-2.5 https://datatracker.ietf.org/doc/html/rfc3658#section-2.5 [2] https://datatracker.ietf.org/doc/html/rfc3658#section-5 https://datatracker.ietf.org/doc/html/rfc3658#section-5 [3] https://datatracker.ietf.org/doc/html/rfc4509#section-2.1 https://datatracker.ietf.org/doc/html/rfc4509#section-2.1 [4] https://datatracker.ietf.org/doc/html/rfc4034#section-5.3 https://datatracker.ietf.org/doc/html/rfc4034#section-5.3