4 ms·
> DNSSEC is highly useful tho Not as it's deployed today. Since over 80% (conservative guesstimate) of the zones that most people care about are not signed, i
by PreInternet01 3y ago
> DNSSEC is highly useful tho
Not as it's deployed today. Since over 80% (conservative guesstimate) of the zones that most people care about are not signed, it's pretty much useless.
The 'evil ISP or IT MITMs my DNS traffic' scenario is much more effectively addressed with DoH (since it only requires clients and some resolvers to coordinate, not the entire Internet, and it looks like regular HTTPS, which implementers already understand how to deal with, as a bonus).
And the 'evil government redirects some or all zones' play is still very much possible even with DNSSEC, since, guess who ultimately controls the keys.
Even if you think that making the latter scenario more difficult to implement is worth it, getting more people to sign their zones is a losing battle, since they're very much likely to self-DoS themselves in the process, significantly reducing their enthusiasm...
- jeroenhd 3y ago> Since over 80% (conservative guesstimate) of the zones that most people care about are not signed, it's pretty much useless. Depends on where you live. Last time I checked, about 70% of the top 25k .nl domains were signed. .ch and .se also have a lot of DNSSEC domains.
- PreInternet01 3y agoYes, I'm aware of the .nl situation in particular, and... it only underscores my point? If those .nl domains dropped off the Internet tomorrow, that (while of course very inconvenient for lots of people) wouldn't cause more than a tiny dip in global traffic. The benchmark here is how much of, say .com and .net combined, is signed. And that's around 4% (4.5M signed zones out of a total 170M, give or take). Because of a well-intended mandate, most .nl domains are signed by their registrar, which generates and holds the private keys. So: the very same entity responsible for enabling domain delegation also secures that delegation. Virtually nobody generates and supplies their own DNSSEC keys when registering their .nl domain. So, a government looking for someone to lean on to modify a delegation, doesn't need to do that much extra work for such 'secure' zones, do they now? From a consumer perspective, visiting digid.nl (signed, probably with their own keys, kept in a nice HSM somewhere!) vs. ah.nl (not signed) offers no meaningful extra privacy or security: when not using DoH, their ISP and anyone else in the middle will still have a pretty good idea what they're up to, and can strip off the 'hey, tell me about your signature' bits in any requests, leaving the client unable to tell the difference in the first place in most situations. In case of a DNS hijack, the consumer security implications are exactly the same for both login (digid.nl) and shopping (ah.nl): their browser or app will refuse to connect, because DNS is already a negligible factor there, and it's the TLS certificate that makes the difference. That, combined with the very real danger that turning on DNSSEC makes a zone unresolvable for hours or even days on end, makes most people a bit wary about doing do. And they're absolutely right.
- jeroenhd 3y agoDNSSEC doesn't provide privacy. It was never designed to. If you want privacy, use ODoH. What it does offer, is tamper detection. I don't trust Cloudflare enough to always provide me with the right DNS data even if resolving the domain happens over TLS, and that's the part of the chain DNSSEC covers. DNS servers don't use DoH to resolve records, so the MitM risk remains. In my experience, the practical risks of enabling DNSSEC are minimal. Some broken (often Big Tech) DNS providers have had issues in the past (Amazon, notably) but every major DNS provider I've used has never let me down, and that includes some of the cheapest domain servers on the market. You may be as wary if you want to be, but .nl proves that the risks of DNSSEC are quite minimal in practice if the TLD registrar is competent.
- tptacek 3y agoHe just explained why it doesn't provide the tamper detection you think it does.
- tsimionescu 3y agoPeople in the Netherlands still use Google, Facebook, YouTube etc and other international servers that are not signed.
- tptacek 3y ago95% is a much closer number.
- JackSlateur 3y agoDoes that matter ? Unlike IPv6, everybody who deploy dnssec gets the full benefits, regardless of what others are doing : you just need to get a fully-DNSSEC-supported chain from the roots to your zone.