4 ms·
> Slack had a multi-hour total sitewide outage earlier this year that came from attempting to turn it on. I don't particularly want to defend DNSSEC here but S
by xtnd53 4y ago
> Slack had a multi-hour total sitewide outage earlier this year that came from attempting to turn it on.
I don't particularly want to defend DNSSEC here but Slack picked Route 53, who both have had and continue to have well known compliance issues with DNS, and they expected them to get DNSSEC right. I'm a little surprised it's gone as well as it has and that they still have DNSSEC on.
Apple's recent revisiting of DNSSEC is possibly the only glimmer of hope for more mainstream adoption of DNSSEC. Their software's got a large installed base and their API is opt-in for DNS consuming software. It'd be nice if more DNSSEC implementations made DNSSEC opt-in but the evangelical DNSSEC set wouldn't abide that.
> I think we've more or less established that a top-down government-controlled PKI is not the future of Internet security. Ending the 26-year DNSSEC boondoggle would free us up to explore alternate models with clearer, more realistic trust models.
I don't think that's clear at all. What is clear is that the DNS hasn't moved much in that period and that the only things that have been adopted are things that authorities and resolvers can silently implement. Putting a fork in DNSSEC won't change much. At this point whatever replaces DNS will be how this space gains some security.