4 ms·
https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
by whyever 4y ago
https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/
- teddyh 4y agoAnd yet here we are, eight years later, DNSSEC adoption still growing.
- mike_d 4y agoThe rate of DNSSEC signed zones is growing, but the number of recursive resolvers that hard fail on validation failures is static or going down. Unfortunately the user experience for a DNSSEC signature failure is so bad, the only option if you run a large ISP or corporate network is to just use the answer you get anyway.
- teddyh 4y agoSince (regrettably, for other reasons), many people seem to be moving to use centralized resolvers which all, incidentally, do validate DNSSEC strictly, I doubt whether “number of recursive resolvers” is a valid proxy for “number of users using DNSSEC validation in practice” anymore. In fact, I see a lot of people advocating for using centralized resolvers, and not even once have I seen a counter-argument in the form of DNSSEC validation being a problem.
- tptacek 4y agoWhat does it matter if your centralized resolver across the Internet is doing DNSSEC? The same on-path attacker DNSSEC was designed to address can defeat DNSSEC on the path between you and the resolver. It's a baffling design.
- teddyh 4y agoIt matters because the topic was whether DNSSEC is growing or not, specifically whether more or fewer users are using DNSSEC validating resolvers. You’re not just moving the goalposts, you’re changing the topic entirely.
- mike_d 4y agoThe horse has been beaten to death - DNSSEC is dead. It continues to see adoption on the authoritative side because turning it on in a basic state and letting it limp along costs almost nothing. Many recursive servers do validate DNSSEC, but disable it on a per-zone basis when validation failures happen and users start to complain. tptacek raises an additional good point that DNSSEC does nothing to protect the last mile of a query. It also provides zero confidentiality. dnscrypt was always a superior implementation, but saw little uptake because people blindly believed the DNSSEC propaganda.
- teddyh 4y agoFrom my perspective, DNSSEC is very much alive, and moreso every year. At work, we only ever see requests for more DNSSEC from everybody; both customers and TLDs/registries. Nobody at conferences, both formally and in informal conversations, has said anything against DNSSEC in principle. I used to say that I ever only saw one person argue against DNSSEC; and it was here on HN. I guess that I can now say that it is two people, both here on HN. If validation failures were that common, I would think I, working at a domain registrar and authoritative DNS provider, would hear about it. The last mile problem would be solved by DoT/DoH, no? If anything is a “dead horse”, it’s dnscrypt. Are you claiming that DNSSEC is some sort of industry conspiracy?
- tptacek 4y agoGrab any list of the top domains on the Internet. My go-to has been the "Moz 500" --- I don't know what it is, or whether it's any good, but it's easy to get. Then write the trivial shell loop to `dig ds $domain`, and count how many of the top domains are signed. Some patterns will emerge: government sites, unsurprisingly, have subscribed themselves to the de jure government PKI that DNSSEC is, and commercial sites overwhelmingly do not. It's very easy to just check this for yourself. There are increasing numbers of domains signed every year, because registrars and product companies have baked DNSSEC in as a feature. But the vast majority of zones don't matter: nobody ever looks anything up in them. The figure of merit is how many important zones are signed.
- xelle 4y ago> `dig ds $domain` Amusingly for this method to work the resolver must understand DNSSEC. This is because DS records exist solely at the parent side of a delegation. A resolver that is not aware of DNSSEC will look to the child as it would for any other kind of record type.